Computer Crime: Insecurity in Numbers

Ivars Peterson · Science News · 1982

The computer is an innocent who will reveal anything it knows, provided it is asked in the right way. By manipulating its digital psyche, a person can create, destroy, divert or change information. Anyone can steal something from a computer's memory yet leave the valuable behind and show no trail. As computer networks increasingly interlace society's fabric, more and more organizations and individuals entrust their most valuable possessions and money to computers. And, increasingly, they getting burned. Students have altered grades, bank employees have shifted pennies from customer accounts into personal hoards, government workers have used or sold sensitive information, and many have taken free rides by stealing computer time for their own purposes. A recent report from the U.S. General Accounting Office says computer systems in government agencies are highly vulnerable to fraudulent, wasteful, abusive and illegal practices. A clerk manipulated input at a Department of Transportation computer to steal more than $800,000. Similarly, the Social Security Administration lost more than $500,000 in disability benefit funds. Internal Revenue Service employees obtained refunds by preparing fraudulent income tax returns for input to a computer. At least 30 employees had unauthorized access to the Department of Agriculture's computer and data files. Some used the computer to perform outside consulting work, to gain access to and use proprietary data, and to make unauthorized and premature disclosure of considered by Agriculture to be highly sensitive, says the report. Computer data systems often contain a high concentration of valuable and sensitive information, such as a corporation's mailing lists and customer accounts, and the government's income tax data. This is susceptible not only to deliberate attack but also to errors. In large amounts of data, errors very difficult to discover and correct. Large computer systems need a reasonable level of protection. However, few company executives and government agency officials understand how to provide that protection. Leslie D. Ball of Babson College in Wellesley, Mass., writes in the April 1982 TECHNOLOGY REVIEW, Industrial security and bank security fairly well understood, but computer security is not. Managers know that sensitive papers should be locked up, but they often less able to grasp how to secure electrons flowing in wires or electromagnetic waves traveling across the country. In addition, new technology creates new problems. As word processors replace typewriters, these small computers (sometimes connected to a company's central computer) easy to misuse. Typewriters don't store once a report is finished; word processors keep the data on file in the system. Robert S. Gordon, executive vice president of Burns International Security Services, Inc., said in his keynote address at the 1982 Carnahan Conference on Security Technology, computer systems reaching the market so quickly that security for these systems is almost an afterthought. Many people still imagine a company's computer as a set of large metal cabinets with whirling magnetic tapes and flashing lights, punched cards and display screens, all collected in one large, air-conditioned room. In the past, computer security consisted of protecting this computer room by using guards, elaborate locks, magnetic card identification and other physical means. If the computer room was inviolate, then so was the computer. In institutions like universities, often the security arrangements were minimal, if they existed at all. Computer systems now quite different. Terminals, which may be scattered throughout a building or around the world, interconnected in complicated networks. Telephone lines and satellites transfer messages from one computer to another. Citibank, for example, electronically processes more than $30 billion a day for its customers. Its 200 branches in 100 countries linked by telephone lines with major switches in Hong Kong, London, Bahrain and New York. An error or a theft potentially can have an enormous price tag. These networks can be vulnerable in surprising and unexpected ways. At the Dalton School in New York City, four 13year-old students used a classroom computer and telephone line to break into a Canadian data network and gained access to the files of 22 companies. In another case, a group of teenagers found discarded systems manuals in the trash bins behind a company's building and obtained enough to shut down the company. In Chicago, two high school boys reached the DePaul University computer by telephone. Their home computer randomly generated thousands of possible master account codes in a matter of seconds until they found a code number allowing them into the university's computer. By changing all the master codes, during their romp through the computer, they prevented the university from using the system for a week. Unauthorized computer hitchhikers have used ARPANET, the Defense Department's computer network for research and development contractors, for passing along messages and playing games. Friends who had access to terminals in the network often provided the needed telephone numbers and passwords. In a widely publicized incident earlier this year, students at the University of California at Berkeley were credited with discovering a flaw in a computer operating system that allowed a user at one terminal to trick the computer into thinking he was another user working at a different terminal. Thus, he could browse through anything to which the other user had access. The security problems and needs in computer networks dramatically different from earlier concepts of computer protection. Safeguards written into computer programs and the use of encryption and secret codes, in a sense electronic fences, become more important than physical means of protection. Now, security experts speak of information systems security, because the entire system, including all its links and terminals, must be considered. There more than 100,000 computer sites in the United States and Europe that constantly talking to one another transferring funds, transmitting critical data. The United States has more than 3 million computer terminals, many of which have access to central computer files. More than 500,000 personal computers have been sold. Add intelligent office machines like word processors and automatic tellers at banks, and the poten-

Read the paper · More papers on PaperTik