Slashdot Mirror


Forget Phishing Just Buy Personal Info

Iago writes "If you need information about a person in Moscow, just go to the market and buy it. The Globe and Mail reports that along with the usual pirated software, cd's etc. you can find out information such as the bank records of your competitors, motor vehicle information and tax returns. The question is, how much of this information is being sold in other countries, perhaps in a more sophisticated manner?"

29 of 163 comments (clear)

  1. Known about this for years by pcmanjon · · Score: 5, Interesting

    They've been doing this for years in other countries. What most people don't realise is that most of these stories you hear about personal information/security breaches (Lexis Nexis, etc etc etc) usually goes to thugs like this.

    These thugs sell this information to people in the black market. This isn't new stuff neither, the news just seems to hover on this and "identity theft" a lot recently. It's been happening since the 80's.

  2. A better question by Anonymous Coward · · Score: 4, Interesting

    A better question is, how much of this information is real?

    1. Re:A better question by temcat · · Score: 4, Interesting

      Most of it is real, believe me. Whay fake something as big as countrywide database when you can easily bribe the right person and get the real thing. Recently there was a scandal when a Central Bank (!) database was stolen. But this is for big boys; as to the general public, stolen mobile operators databases are very popular here, because we don't have official telephone directories with personal phone numbers.

  3. Disinformation? by Anonymous Coward · · Score: 5, Interesting

    A massive flood of fake information would dilute the value of stolen i.d. right?

    1. Re:Disinformation? by lifeblender · · Score: 3, Interesting

      Not at all. It would increase the value of trusted stolen ID information. In the end, it would just make thieves use more sophisticated social networks, etc. They'd get around it, and would be willing to pay more for real data, since the work that went into collecting it and verifying it was greater.

      To sum up, it's still supply and demand, and you're talking about diluting the supply. That means that, for those who can get at the 'good stuff', it's worth more.

      On the other hand, if the FBI and the credit card companies were to engage in honey-net operations, then we're talking.

      On a related note, I just got a note from my credit card company saying that I could make a temporary credit card number for online purchases. Seems like things are looking up, if only a bit.

      --
      Playing pornographics games during the day is evil! Play at night!
  4. What, /.? You don't like it? by chocolatetrumpet · · Score: 4, Funny

    But, I thought information wants to be free?

    --
    Spoon not. Fork, or fork not. There is no spoon.
    1. Re:What, /.? You don't like it? by RAMMS+EIN · · Score: 3, Interesting

      Yes. If this information were Free, at least we would be more aware of what was happening. And criminals wouldn't be getting paid for it. This way, the criminals and the people with money benefit.

      I personally don't think I care if my and everyone else's "personal" information becomes public. I don't think there is anything extremely interesting about it. People already find out my phone number, email address, street address, bank account number, sometimes even credit card number, user name, real name, etc. etc. etc. as it is.

      All that said, I don't think it's necessary to make all everything publicly accessible. It does open the door to more fraud (although it can also help catch fraudsters more easily!), spam, etc. So let's say that public information wants to be free, and private information wants to stay private?

      --
      Please correct me if I got my facts wrong.
  5. Because as a wise person once said... by truckaxle · · Score: 5, Funny

    Sell a man a phish he can scam for a day, but teach him how to phish and he can scam for himself for a lifetime.

  6. Buy from gangster, get burnt by Willeh · · Score: 4, Interesting
    Yeah right, and what's to say this information is actually valuable? TFA says that at least some of it is, but just like bulk email lists there's bound to be a lot of chaff in all of it, due to natural entropy of data, etc etc.

    And it's not like these lists ever get refreshed much, so what you end up with is increasingly less useful data in these lists, and the vendors don't even care about it. It's just the nature of the beast (and the overall state of former Russia, where anything goes).

    --
    Will wank off Linus Torvalds for fame.
    1. Re:Buy from gangster, get burnt by Peeteriz · · Score: 3, Interesting

      The things you can buy in Moscow market are the real thing - Russian IRS database, with the income information as accurate as the authorites have it, the living addresses are the ones that the police use, etc.

      If it says 'Tax returns 2003', then it really is the tax returns, as they were for 2003, complete with the ability to easily search for, say, addresses and family relationships of persons in your neighbourhood with more than 100,000$ income last year.

    2. Re:Buy from gangster, get burnt by RAMMS+EIN · · Score: 3, Funny

      ...and the overall state of former Russia...

      Dude! When did the revolution happen? I'd better go and update my little database here.

      Are you sure about your sig? ;-)

      --
      Please correct me if I got my facts wrong.
  7. Another example of security through obscurity. by Behrooz · · Score: 4, Insightful

    The question is, how much of this information is being sold in other countries, perhaps in a more sophisticated manner?

    All of it, of course. Sooner or later we're going to have to get used to the idea that the concept of preserving privacy as a society disproportionately benefits individuals and groups with the resources to acquire and disseminate information regardless of the obstacles in their way.

    It's too late to save privacy as most people currently envision it. What we need to be doing as a society is focus on transparency and equality-- ensuring that all parties in the social contract stand on an equal footing with regard to what information is publicly available. Secrecy is most dangerous when the powers that be insist that it be one-sided...

    --
    "We have to go forth and crush every world view that doesn't believe in tolerance and free speech." - David Brin
  8. It's just going to get worse by The+Slaughter · · Score: 4, Insightful

    I think this has always been around, but with the proliferation of the digital era, it becomes easier to make a thousand copies of something.
    Look at medical records, it used to take a few minutes while they looked for your chart. At the medical clinic I currently go to they can locate you instantly. When you go into the doctor's office, he has your information on-screen. If something like a patient's chart goes missing, there's physical evidence that it's gone. But if a computer is poorly secured, you may not ever realized it was compromised.
    What really bothers me is who is purchasing this information. My medical records would be pretty harmless to most people, but what if a coworker with a grudge were to find out about a deadly allergy I have? There's always that scary potential you don't necessarily think about. What if a terrorist uses your identity to get into the country and commit nefarious deeds? Could you be imprisoned while they go free?

    1. Re:It's just going to get worse by RAMMS+EIN · · Score: 4, Insightful

      ``What if a terrorist uses your identity to get into the country and commit nefarious deeds? Could you be imprisoned while they go free?''

      With the current paranoia, definitely. It's better to be safe than sorry, so let's send back that plane that has someone on board who might be a terrorist (and, after all, anybody could be a terrorist), and let's keep these people safely locked up without a trial, until maybe someday we have some evidence against them, or perhaps for them.

      Seriously. The principle that you're innocent until proven guilty is a healthy one. There's also a reason this has to be proven in front of a judge. These people are trained to be impartial, and to spot weaknesses in the argumentation and evidence on both sides. People in general are easily swayed, especially with media influence.

      Now, to return to your issue about computers, that's a very good point, and highlights an important problem. People think computers don't make mistakes, and information that is stored there and backed up is safe. Both of these are pretty much correct. However, that does not mean that what comes out of a computer is correct in any sense. People still make mistakes when entering information, and I think we here all know how sad a state computer security is in.

      Especially falsification of information from inside is a very real threat. In most applications I have seen, this leaves no traces unless you want it to. Very different from handwritten information, where it's easy to see that something was written by a different person, and investigation may even reveal who that person is. If not by the handwriting, then by the fingerprints.

      Many of these fallbacks are simply not available in computer systems, and with computers being the backbone of virtually everything organized, I think we ought to be really concerned. And, I might add, the fact that most of these are running known faulty software and operated by non-computer-savvy people does not make it any better. Nor does the fact that the workings of said faulty software are hidden.

      --
      Please correct me if I got my facts wrong.
  9. not only in Russia by Mrs.+Grundy · · Score: 4, Insightful

    What is going on in Russia IS a little scary, but is it really any different that buying the same information from one the businesses operating in the US like choicepoint? The government and industry buys information from HUGE databases legally here in the united states, but for some reason people make it seem scarier when it is a Russian kiosk instead of an american corporation even though both exercise about the same amount of restraint and ethics concerning to whom they will sell information.

  10. I'm not surprised by Underholdning · · Score: 4, Insightful

    The rule of thumb is: Do not worry about the means of transport, but the destination.
    In other words - don't worry if the encryption used to send the data is 128 bit or 1024. No one will bother try to sniff'n'hack it anyways. Worry about whom you're giving your info to. Sure - they may have cheap DVD's, but in order to sell you cheap goods, they must save money in other areas. Security is (sadly) one of the first things to go.

  11. not just Moscow by Ingvar77 · · Score: 5, Interesting

    In every major Russian city you can obtain almost for free a database with phone numbers(including cell), addresses, car registry and pasports for all citizens of this city.
    Even more, it's hard to find a PC in my own city that doesn't have a "Megapolice" database, which contains all above information accessible throught a single easy-to-use interface.

  12. Everything has its price. by Shag · · Score: 3, Funny
    The question is, how much of this information is being sold in other countries, perhaps in a more sophisticated manner?
    The answer to that question is available... for a price. ;)
    --
    Village idiot in some extremely smart villages.
  13. Re:That old saying... by jrockway · · Score: 3, Funny

    Sorry to hear about your shift key.

    Also, I like how you can't put a period after "St." but can end every sentence with ... three periods. You only need one! ;)

    --
    My other car is first.
  14. Grammar? by noidentity · · Score: 3, Funny

    Forget grammar just stick words together see like this isn't that easy

  15. India by romit_icarus · · Score: 3, Informative

    It's being sold in India. I've met "vendors" who do the round of direct marketing agencies peddling CDs for information. The last I checked, about a year ago, a data CD came for 10c/record...

  16. With all this Phishing in the news... by Tink2000 · · Score: 3, Funny

    I've given a lot of thought to the subject lately, and really, I've decided I don't care much. In fact, I honestly believe that anyone who stole my identity would after a quick perusal of what they've stolen feel guilty and probably credit me a couple of hundred bucks or so.

    Hey, you can't steal what isn't there, and my credit is already wrecked beyond belief. You'd have to be a pretty desperate scammer to steal my identity.

  17. "Private Eye" CD by Anonymous Coward · · Score: 5, Interesting

    A few years ago in Israel a CDROM started circulating with information about more-or-less the entire population. The database was probably leaked from the Ministry of Interior. It was originally used by a private investigations firm but a copy leaked and started circulating freely.

    IMHO, once it's out there it's everyone's civil duty to get a copy, just to level the playing field.

  18. Re:Miene Final Solution by Frodo+Crockett · · Score: 3, Funny

    You forgot the sheep. It gets lonely out in the woods.

    --
    "The newly born animals are then whisked off for a quick run through a giant baking oven." --heard on Food Network
  19. Buying Personal Info, U.S. Style by divide+overflow · · Score: 4, Interesting


    The easiest way to buy personal information here in the U.S. is to set up a fake company, then request the desired information from one of the major credit bureaus: Experian, Equifax, TransUnion, or ChoicePoint. Back in February ChoicePoint admitted to releasing the information on at least 145,000 consumers to fake companies.

  20. What is unusual about this? by dan+dan+the+dna+man · · Score: 4, Interesting

    In the UK I've had the ... pleasure (?) ... of knowing some exceedingly dodgy people with very good technical skills. This information has been available to criminals with the requistite amount of cash as long as hackers (sorry crackers) decided they could make a fast buck doing companies rather than pootling around insecure university networks.

    Nothing new here and it certianly isn't limited to dodgy stalls in Moscow markets or corrupt outsourced callcentre employees.

    --
    I don't read your sig, why do you read mine?
  21. I hate to disappoint you by plaxion · · Score: 3, Funny

    ...but there aren't enough moderation points available in the /. system to stave off the flow of bad "In Soviet Russia..." _AND_ "PROFIT!" jokes that are going to flood in from this one.

    If you think you have a good one, please save someone a mod point by keeping it to yourself, because if it isn't already redundant, it soon will be.

    This message brought to you by the Moderator Points Association of America (MPAA) *ducks*

    --
    I'm commenting on this story to prevent myself from burning moderator points on useless comments like this one ;)

  22. Well, I hope by SimianOverlord · · Score: 3, Funny

    that they haven't scammed detail from places like say, the NYTimes subsriber database. "Mr A Butthole, Kansas" and "Phil McCrackin, Washington" might find unwanted junk mail winging their way towards them.

    --
    Meine Schwester ist sehr, sehr reizvoll - Nietzsche
  23. Old trick with new methods by Peyote+Pekka · · Score: 4, Informative
    The difference is that since the 80's it is much easier. Personal data on Windows servers has made getting personal data that much easier. Doing that and connecting it to the Internet is just asking for a gross- or willful-negligence lawsuit. Take the case of the recent Mastercard incident: (sorry, link in Finnish)

    People burned by that one could go for a class action lawsuit against either Mastercard their service supplier or the software vendor or a combination. There's no excuse for using tools known to be defective in a networked context.

    Increasingly that said same vendor has been associated with breaches of security and failures. A year ago it was voting machines now this...