Closing the phishing hole: fraud, risk, and nonbanks
Closing the phishing hole: fraud, risk, and nonbanks
复制标题
堵住网络钓鱼漏洞:欺诈、风险和非银行机构
DOI:
--
复制
发表时间:
2007
期刊:
影响因子:
--
通讯作者:
Ross J. Anderson
中科院分区:
文献类型:
--
作者:
Ross J. Anderson
Online fraudsters use a variety of nonbank payment services to launder the proceeds of crime. People had assumed that traceability was the key. However, investigation reveals that revocability is more important. Fraudulent payments within the banking system can be pursued and recovered with a reasonable probability of success; but once stolen funds are used to buy transferable financial assets such as eGold, recovery becomes much harder. This suggests that much of the benefit that could be obtained from regulating nonbanks more closely can be got by greater transparency about counterparty risks. I also look at broader issues; just as adequately regulated offshore financial centres can benefit the global financial system by providing competition, so also nonbank payment systems can play a useful competitive role. A further issue is the confusion between identity and traceability that has crept into compliance procedures since 9/11; I argue that there has been too much emphasis on the former at the expense of the latter. The current FATF rules impose unnecessary burdens, particularly on the poor, while not doing enough to facilitate rapid recovery of stolen assets. Future regulation of nonbank payment services must take account of this. Anonymous or unverified payment mechanisms can be tolerated, particularly for low value instruments, so long as stolen funds can be quickly traced and recovered. One must also be cautious about liability. Many nonbank payment systems use contracts that attempt to make them judge and jury in disputes with customers – risking a race to the bottom that would undermine consumer protection, and moral hazard which exacerbates operational risks. Only payment service providers can fight fraud effectively, as only they have access to all the data, and the ability to evolve their systems. Consumer protection thus cannot be ignored in payment system resilience. Introduction – fraud and phishing Since about 2000, there has been a growing realization that the management of information security risks crosses the boundary between technology and policy. Systems often fail not so much for technical reasons, but because incentives were wrong; often the people who operate a system are not the people who suffer the full costs of failure. (Indeed, systems are often designed deliberately to externalise risk.) This has led to the growth of a new discipline of security economics, which now has over 100 active researchers and two annual conferences. One question asked by the Federal Reserve when asking me to give this talk was: what might a security economist say about online fraud and its associated operational risks in the context of nonbank payment services? Since about 2004, online crime has become big business. Before then, a typical ‘hacker’ was a teenage prankster who tried to infect machines or knock out networks to impress his peers; and while there were some online scams, they tended to be sporadic and disconnected. That has now changed. People now write computer viruses not for fun, but for profit. Infected machines are organised by the thousand into botnets that are rented out to send spam, conduct service-denial attacks, and host fraudulent websites. The critical change has been the emergence of an underworld economy, so that villains can specialise and trade with each other. The most rapidly growing online crime appears to be phishing, in which victims are lured by an email to log on to a website that appears genuine but that actually steals their passwords. It started in 2003, with half-a-dozen reported attacks. These were both crude and greedy; the attackers asked for all sorts of personal information, and even for ATM PINs, which made many customers smell a rat. By 2004 the phishermen had raised their game, using copies of genuine bank emails and websites, and better psychology. By 2006, losses had climbed to £35m in the UK, and nine figures in the USA. Growth continues at a phenomenal rate, with the target list now including not just large banks but also nonbank payment services such as PayPal and large retailers like Amazon. Although it is easier for crooks to build a copy of a bank’s website than it is to build a bogus bank branch in a shopping mall, the infrastructure required for a successful phishing attack is still not entirely trivial. But this is where the growing underground economy is coming into its own. An American software engineer may now write malware used by a Romanian botnet herder to take over thousands of machines; he in turn rents them out to a Russian phisherman who sets up the bogus website and spams the bank’s customers. There follows a chase in which money is moved from compromised accounts. These accounts are traded; there are also organisations that recruit ‘mules’. So a number of gangs remove money from compromised accounts, pass them through other compromised accounts or mules, and finally move them through a nonbank such as 1 For a recent survey article see ‘The Economics of Information Security – A Survey and Open Questions’, Ross Anderson, Tyler Moore, Softint 2007 (Jan 19–20, Toulouse); at http://www.cl.cam.ac.uk/~rja14/Papers/toulouse-summary.pdf 2 Another was ‘Will online gambling be the killer app that makes nonbank payments popular?’ However, gambling is moving to Second Life, to the point that the FBI raided it: http://www.reuters.com/article/technologyNews/idUSN0327865820070404? 3 R Clayton, ‘Techno-Risk’, at Cambridge International Symposium on Economic Crime 2003, at http://www.cl.cam.ac.uk/~rnc1/talks/030910-TechnoRisk.pdf 4 Mules are often poorly-educated elderly people, recruited by ‘work from home’ ads, who believe they are earning an honest 10% by remitting funds they receive in their bank accounts onward to an ‘exporter’ overseas eGold or Western Union. Finally the stolen money is taken from the payment system by specialist cashout operators, who may belong to another gang entirely. As with Adam Smith’s pin factory, specialisation brings the criminals great productivity gains. There are variants such as ‘pharming’ in which the deception is not carried out on the customer directly but on the infrastructure; for example, home routers may be taken over and configured to direct bank customers to malicious web pages instead of the real ones. Much work has been done recently on technical defences against phishing and pharming, but there is a growing realisation that technology can only do so much. First, there is the classic security-economics issue that everyone wants someone else to solve the problem; at a recent UK conference, the government wanted citizens to take more responsibility for their own safety online, while banks blamed the government and the ISPs, and everyone else was eager to distance themselves from the problem in other ways. This liability dumping is endemic; it has been modelled by Hirshleifer and Varian in terms of whether the security of a system is determined by the sum of the defenders’ efforts, the maximum effort that any of them makes, or the minimum effort that any of them makes. In the last case the actual defense effort may fall particularly far short of the social optimum. Second, the standard security mechanisms shipped with commodity PCs are not really fit for purpose. The SSL/TLS protocol was designed in the mid-90s to dump compliance costs on users, and again, the underlying reason was economic – companies competing for dominance in markets with strong network effects (as Microsoft and Netscape were in the browser market at the time) are motivated to put their complementers’ convenience above their customers’ security. A competing protocol that would have been more resistant to phishing – SET – was also resisted by the banking industry because of higher infrastructure costs and by consumers as it eliminated chargebacks and dumped liability