Slashdot Mirror


Kinko's Spy Case Illustrates Public Terminal Risk

tealwarrior writes "CNN reports in this story that a hacker by the name of Jiang was charged with installing keystroke loggers to record passwords in 14 differnet kinkos in New York. These were then used to open bank accounts online. The article mentions Jiang signing people up for accounts with GoToMyPC then then using their own machine to open bank accounts. Also mentioned are similar schemes perpetrated at Boston College." Be careful out there, folks. Sometimes there's even sneakier things than just stealing one's cookies.

32 of 383 comments (clear)

  1. What do people expect? by fadeaway · · Score: 4, Insightful

    Why would anyone consider using public access points to access private/secure data? That's just asking for trouble.

    It's amazing. 99% of people have the sense not to give out their CC # over a payphone in a crowded bus terminal. Online Banking however, why not. Silly.

    1. Re:What do people expect? by squaretorus · · Score: 4, Interesting

      99% of people have the sense not to give out their CC # over a payphone in a crowded bus terminal

      Are you sure? I've been sitting on a train as a guy opposite sat with his card on the table shouting the numbers into his mobile phone (he was ordering flowers for his wife - anniversary - £100 bunch - no ribbon - she hates ribbon - thinks its a waste - and nothing with those really thick stems - she always complains about those too - and just put 'hey' on the card - yes - just 'hey') gave his address for delivery, his postcode, his home and mobile numbers and his wifes name (Ruth - kind of old fashioned a name I thought) and a few other bits. Practically enough to get a passport with!

      Maybe he was the 1%. So far as I could tell I was the only one logging all this info into a palm at the time tho - so no harm done!

  2. is this viable for a class-action lawsuit? by squarefish · · Score: 4, Interesting

    I used a NYC Kinko's during H2K2 last year on 7th Ave. I've been unable to find it now due to dilution of the story, but I found on online article the other day that said this had actually gone on for two years and that the person that discovered it had used a computer at one of their stores on 7th Ave, but they have two. I used the one at 500 N. 7th, store # 0961

    I called their customer support line on Wednesday as soon as I saw this article, and they said they didn't know anything about it- the person I spoke to called me back and said that their corporate office would get back to me by the end of the day.... I'm still waiting.

    I called the store directly last night and the manager, sounding like he was lying through his teeth, told me that they were absolutely not one of the stores.

    So, I've very interested in knowing if this has class-action lawsuit potential since Kinko's was prosecuting this case and obviously had no intentions of notifying their customers of the risk they were at while using their store. If there is an existing lawsuit, how do I find it? Thanks!!!!

    --
    Creationists are a lot like zombies. Slow, but powerful and numerous. And they all want to eat our brains.
  3. Out-of-order username & password entry by G4from128k · · Score: 5, Insightful

    I use out-of-order username and password entry on public terminals. I type a couple of letters of either username or password, click in the middle of the typing entry in the other field, type more letters, etc. It only takes a bit of concentration to remember which password letters I have typed. Unless the logger is doing a full scan of exactly where I click, they get a disordered, mixed version of my username and password broken up by numerous mouseclicks.

    --
    Two wrongs don't make a right, but three lefts do.
    1. Re:Out-of-order username & password entry by Anonymous Coward · · Score: 4, Informative

      Curiously as you are using a mac-looking name, 2 of the most popular keystroke loggers for macs (when I used them, which was up until just before the OSX days) would take note of exactly this, and still get your password and your random typing as separate strings. I have no experience with PC loggers as I haven't investigated them since, I've learned to never trust a machine with details I couldn't afford to lose.

      I used to use this exact same technique, then tried it on a couple of loggers I suspected. Some coders have too much time on their hands

    2. Re:Out-of-order username & password entry by jmichaelg · · Score: 4, Informative
      Under Windows, logging clicks isn't any harder than logging keystrokes. My macro program, mgSimplify uses the same dll to keep track of both events.

      Instead of trying to be clever, you're probably better off not trusting a publically accessible computer.

  4. Stupid users, Stupid Kinkos by jsailor · · Score: 5, Interesting

    You might be amazed at what people save on the hard disks. I've found all sorts of stuff including insurance letters complete with SSNs, addresses, etc. (of course, I've found similar stuff left on the copy machines - lower tech stupidity)

    Easy Everything, now with a site in NY as well, essentially netboots all the PCs after each user so even if the previous performed some evil, the next user gets a new system free of any malware. This doesn't seem like it would be too hard for Kinkos to do as well. If you've been to a Kinkos in NY, you would know that the copy specialists in the stores are not maintaining the machines.

  5. Virutal keyboards by bogado · · Score: 4, Interesting

    Banks in brasil are using virtual keyboards, they are a numeric pad that apear in the screen with the numbers in a random order and/or in a random position. You must then click the password with a mouse. Of course if you own the machine you can save the HTML and mouse clicks to analise it latter, but it makes the life of keyloggers harder.

    --
    []'s Victor Bogado da Silva Lins

    ^[:wq

  6. Am I the only one not surprised? by xThinkx · · Score: 5, Interesting

    I mean, come on, there have to be tons of computer geeks like me out there that look at public libraries, kinkos, office max, internet cafes, etc; and think that a keystroke logger could be infinitely damaging.

    Considering any schmuck could pick up a completely software undetectable and almost completely visually/physically undetectable hardware keystroke logger for under $100, this doesn't surprise me. Does anyone think the employee at kinkos getting paid $6/hr cares enough to learn about keystroke logging or check it out?

    Again this brings me back to the opinion that allowing any idiot to do whatever they please on a computer is a rediculous idea. I know this is beating a dead horse, but, do we let people drive a car or fly a plane without a license? Before you jump on my case I'm not saying people should need licenses to use computers, or that computers can physically kill a boatload of people like a car or plane could. What I am saying is that banks might require some for education or training, or even just provide literature, something, ANYTHING to let people know that it's probably not the best idea to do your internet banking from KINKOS!.

    I'd also like to point out that gotomypc.com sucks, if I see one more ad for them, I'm going to gototheirpc and smash the living crap out of it

    --
    Let's get one thing perfectly clear, I did not vote for George W Bush, and I do not endorse what he does or says.
    "
    1. Re:Am I the only one not surprised? by xpulsar87x · · Score: 5, Insightful
      Does anyone think the employee at kinkos getting paid $6/hr cares enough to learn about keystroke logging or check it out?

      Why is it that the general idea of most people that how much you get paid is directly related to how much effort you put into the job? I worked at Staples in high school, i was paid 6.25 an hour, and I did a pretty damn good job I might say. I didn't mope around my whole shift, I'd help people out, learn about things i didn't know (like printers, i don't print anyhting ever so i didn't know much about the technology in em), took time to learn how do work the machines in our copy center, etc etc. You trying to say that becuase Kinko's employees get paid x amount of dollars they won't bother with this stuff? They could be a budding geek like you and me, still in high school or college something, and they certainly would take an interest in it.
  7. Some help, but not 100% effective by Anonymous Coward · · Score: 5, Informative

    As does the strategy of opening Notepad (or some other app), typing a couple of characters into the password box, clicking to Notepad and mashing down the keyboard awhile, etc. until you've completed the password. An intelligent keylogger will only hook certain window classes, but most keyloggers are "all-or-nothing."

    The real solution, though, is don't enter your passwords on an untrusted machine! I went to visit my aunt, uncle, and cousins in Nebraska last month. They know I work online and were totally perplexed as to why I wouldn't use their computer to check my email, my PayPal account, etc. "Well it's gonna take awhile to charge your laptop back up, why don't you just use our computer till then?"

    "Because I don't trust your computer" isn't the kind of thing your relatives want to hear, so I emphasized the fact that I have no idea what's running on their computer. We did have a good discussion about spyware, and I downloaded Ad-Aware and showed 'em how to use it. They actually came up fairly clean (just that "satellite" program, I forget who makes it) but I still wouldn't use their machine for anything sensitive.

  8. Sloppy. by MImeKillEr · · Score: 4, Interesting

    When I worked in support, I was responsible for publicly available PCs. The first thing I did when I took over supporting these was to set policies in place BLOCKING the ability to install ANYTHING by anyone other than the administrator.

    Whoever was doing support for Kinko's didn't do their job.

    Same goes for any other publicly available PCs. Slap policy editor on the system and lock down the ability to install any additional applications, as well as the ability to change the look of the computer. How fscking hard is that to understand?

    Failure to do so leads to incidents like this, as well as makes it easier for someone to install pirated software, pr0n, etc. on your systems.

    --
    Cruising the internet on my TI-99/4A @ a whopping 300 baud!
  9. RTA -- He did not sign up for GoToMyPC... by Fallen+Kell · · Score: 4, Informative

    Jiang did not sign people up for GoToMyPC. That is just how he was caught! Someone HAD GoToMyPC and because Jiang logged on and did what that person had done, he wound up starting the GoToMyPC services, with which, actually controls your home PC. The person who's accounts were being accessed happened to be at home at the time that Jiang used his/her account and immediatly knew that someone had gained access through the GoToMyPC service and contacted the authorities. That is how they caught him... Not him signing people up for GoToMyPC...

    --
    We were all warned a long time ago that MS products sucked, remember the Magic 8 Ball said, "Outlook not so good"
  10. Passwords are an obsolete form of authentication by Dratman · · Score: 5, Interesting

    Even before the Kinko's case, the recent proliferation of fraudulent emails, supposedly from ebay and similar sites, which ask for passwords to be re-entered on a web site, illustrate that passwords are no longer an adequate form of security.

    The most practical alternative at the present time appears to be use of a magnetic stripe card in addition to the password, similar to the authentication process for an ATM. Magnetic stripe readers are now quite common and could be installed on public terminals at minimal expense. Probably the most significant barrier to their widespread adoption is the lack of standard protocols and software packages.

    --
    Sigmund
  11. Re:And this should surprise us? by will_die · · Score: 4, Informative

    You mean like this.
    If I was to do this I would use one of the versions that uses a a private IRC channel to communcicate, that way you never have to go back to the machine again, yet can control it from almost anywhere with a lesser chance of being found.

  12. This is why some banks... by xneilj · · Score: 5, Insightful

    This is why some banks do not request full information for login.

    For example, here in the UK, NatWest bank's online service will ask you for the following secure information to login:

    Three digits from your four digit online PIN (in a random order, like second, first, fourth).

    Three characters from your password, again a random selection in a random order.

    While it initally irritated me that logging on to the system took a little more thought than normal (I have a long password and it's easier to type it out in full than work out what the eighth, fifth, and eleventh characters are), it's probably a much more secure system when people are going to be using public terminals.

    It also makes people less liable to some sort of 'sniffer' attack, since the system dictates which characters to ask for and locks you out after several incorrect attempts. It would probably require somebody to observe more than one login session before they had enough information to do repeat it themselves, and unless you know which order the characters and PIN were requested, a plain keyboard capture program would be ineffective.

    --
    rm -rf / is the evil of all root
  13. Comment removed by account_deleted · · Score: 5, Insightful

    Comment removed based on user account deletion

  14. Re:Funny thing, the name... by aziraphale · · Score: 4, Insightful

    Well, to be fair, Muhammed and Jiang are two of the more common names in the world, simply by weight of population...

    More interesting question: why is it never Amy, or Meiying, or Fatimah?

  15. More info on this case by dki · · Score: 5, Informative

    ...can be found at SecurityFocus.

  16. Keyboard Loggers... by BJZQ8 · · Score: 4, Informative

    There are PS2-connector keyboard loggers sold in various places on the internet...although they're a bit more conspicuous, how often do you check for the presence of one? In a public-access machine, they can be set to record only usernames and passwords...It's just something you have to accept...that someone is probably watching, somewhere.

  17. Bring your own OS? by dschuetz · · Score: 5, Insightful

    One of the initial selling points for NeXT computers, way back when (has it really been 15 years? sheesh...) was the Optical drive. It was a 256 MB, 5"x1/4" hunk of plastic, and the intention was that you could carry your entire NeXTSTEP OS, home files, etc., around with you. Bring it to the public terminal in your dorm's basement, slap it in, and reboot.

    Now, obviously, that didn't work (they were big, slow, and buggy). But today it should be even easier, almost trivial, to do something. Just bring a Knoppix CD with you whenever you go to a public access sytem (assuming they don't lock down the CD-ROM drive). If you can fit it on a business card CD, you can even keep it in your wallet.

    They could even do this at the system-provider level -- have branded, mass-produced, customized versions of Knoppix in each machine, and encourage people to check the CD and reboot before they use it. Of course, this wouldn't work as well with the systems intended for graphic editing, etc. (with AI, Photoshop, etc.), but for simple internet access systems, it'd be pretty good...

  18. Re:And this should surprise us? by Daniel+Rutter · · Score: 4, Informative
    Woo! An excuse to pimp my old reviews of KeyGhost hardware key loggers!

    Review one. Review two.

  19. One time passwords? by cras · · Score: 4, Informative

    Aren't all banks using them? Pretty effectively makes the keyloggers useless. At least the largest banks in Finland do that before giving access to anything important.

  20. OP is wrong by nochops · · Score: 4, Informative

    The article mentions Jiang signing people up for accounts with GoToMyPC then then using their own machine to open bank accounts.

    No, the article does not mention that. The article says that Jiang used a keylogged password to gain access to someone's home machine via GoToMyPC. He then took control of the machine and used it to open a bank account. Similar, but wrong enough to warrant correcting.

    Well, I guess if the OPs aren't going to read the articles they submit, and the editors aren't going to read the articles they post, why should the rest of us read the articles we comment on? Let's just have one massive offtoipc flame-fest! Yay!

    --
    "A terrorist is someone who has a bomb but doesn't have an air force." -William Blum
  21. Re:Magic Lantern by lfourrier · · Score: 4, Insightful

    After all, key loggers have to keep a log somewhere!
    but not necessarly on the PC.

    http://www.thinkgeek.com/gadgets/electronic/5a05 /

  22. Re:Clarification Please! by mblase · · Score: 4, Informative

    Kinko's stores are ridiculously popular in the US, especially near colleges and universities. Photocopies and printing, many are open 24 hours, and they offer computer terminals for rent with graphics and publishing apps already installed. They're so common now that they're practically an entry in the dictionary.

  23. easy everything solution by straybullets · · Score: 5, Interesting

    last time i went to an easyeverything cybercafe i noticed that on logout the pc would reboot and re-install a fresh image of the whole os on the disk. I think it got the image from the network but i can't recall what soft they used to do it (it had a strange name)...

    Of course it takes some more time on rush hour (like 10-20mn) but they have lots of pc so ...

    and also, too bad for installing key loggers then ..

    --
    With that aggravating beauty, Lulu Walls.
    1. Re:easy everything solution by Henry+Pate · · Score: 4, Informative

      I know one piece of software that does they, they used to use it at my high school, it worked pretty well. It's called Deep Freeze, you could do anything you wanted to the computer, and when you rebooted the system was back just the way it was before, with all software installed during the last session gone, everything. You can find it here

      --
      Si Hoc Legere Scis Nimium Eruditionis Habes
  24. What about hardware loggers? by nochops · · Score: 4, Informative

    This would stop a keylogger application, but not a hardware logger between the keyboard and PS2 connector on the motherboard. They're small, and cheaper than software, and will work across any operating system.

    --
    "A terrorist is someone who has a bomb but doesn't have an air force." -William Blum
  25. From a Kinko's employee by catfishmonkey · · Score: 5, Interesting

    I'm a manager at Kinko's.
    You really would be shocked to see the kind of stuff people leave behind on the hard disks and in the copy machines. At least a dozen I.D. cards, birth certificates, credit cards, confidential company files, etc.. are left every day.
    Just yesterday a customer came in and asked if we'd found her credit card. She said she'd left it in the copy machine a week ago and just noticed it gone. We couldn't find it and told her she'd probably wanna go ahead and cancel the damn thing. She replied, "nahh... too much trouble.. it'll turn up someplace".

    What a world.

    --
    The horse is dead. Either fuck it or walk away, but please stop beating it.
  26. Kinko's Security by stinkydog · · Score: 4, Insightful

    I have used a Kinkos machine in Columbus Ohio (near Ohio State) and here is what I found:

    1. Windows 2000 with the user logged in as poweruser or administrator.
    2. Pop up software installed (unknown spyware).
    3. I could not find a USB port so I stood up and moved the PC and plugged in in the back. No comment from staff.

    The only "security" I saw was protecting the billing app.

    SD

    --
    âoeWho knew something as harmless as willful ignorance could end up having real consequences?â
  27. Re:I am typing this now from a Kinkos by BitchHead · · Score: 4, Interesting

    I worked at a Kinko's as a second job for a brief stint, and while I'll agree with you on the wages, I can't say as much for the training that most employees receive. The general guidelines that are given to employees are that the self-serve machines are just that: Self-serve. Don't spend a lot of time trying to explain things on the machines. If someone wants a job done, and can't figure it out on the self-serve machines, they can get it done behind the counter. The same rule holds true for the computers. It's part of the self-serve area. Help people only to the extent of not being discourteous, but the copy associates are not there to tell people how to work their email or perform tasks on Photoshop.
    The majority of the training goes into learning how to work the supplementary process machines (folders, tape and coil binders, bookletizers, etc.) because those are the large batch jobs that bring in the most money. Very few employees, depending on the location and the shift, will actually know how to set up specialized features on the large DocuCenter machines. Day shifters and second shifters will typically run the small batch jobs that need to get out that day, and leave the rest of the work for the night shift. If you want the job done right, bring it there at 3am for a morning pickup. The night shift is usually only 2 people, many times just one (as was the case when it was my shift) and they need to know how to work everything in the shop.
    The computers, however, are not upkept by the individual branch employees. There are regional network engineers who do the initial installation at a branch. After that, there is a Kinko's central hub help desk to take care of any questions that the manager/employees have, and a central station for remote administration of branch networks for a region. The managers are expected to be able to follow a colour coded wall chart in the network closet if they want to move equipment or add machines. Ours was an absolute nightmare. Serious technicolour spaghetti, and totally misconnected according to the wall chart. The managers and employees receive zero training on any network essentials, so don't expect them to know anything about security measures. The manager at the branch I worked at couldn't tell you the difference between a keystroke logger and a timber logger.