0% found this document useful (0 votes)
2 views28 pages

Cyber Crimes: Hacking & Identity Theft

Chapter 5 discusses various cybercrimes including hacking, identity theft, and the complexities of international laws governing online behavior. Hacking has evolved through three phases, from creative programming to malicious activities, and includes various tools and techniques used by hackers. Identity theft and credit card fraud are facilitated by e-commerce, with various methods employed to steal personal information, while legal frameworks differ across countries, complicating enforcement and compliance for businesses operating globally.

Uploaded by

bugs20065
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views28 pages

Cyber Crimes: Hacking & Identity Theft

Chapter 5 discusses various cybercrimes including hacking, identity theft, and the complexities of international laws governing online behavior. Hacking has evolved through three phases, from creative programming to malicious activities, and includes various tools and techniques used by hackers. Identity theft and credit card fraud are facilitated by e-commerce, with various methods employed to steal personal information, while legal frameworks differ across countries, complicating enforcement and compliance for businesses operating globally.

Uploaded by

bugs20065
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

Chapter 5: Crimes

1. Hacking
2. Identify Theft and Credit Card Fraud
3. Whose Laws Rule the Web?
1 Introduction

• Thieves and scammers found ample opportunity to


cheat unsuspecting people in cyberspace.
• Some scams are new or have evolved to take
advantage of online platforms characteristics.
• Crimes in cyberspace affect millions of people and
cost billions of dollars.

2
5.1 Hacking

• What is hacking?
• Defined as “an irresponsible, destructive action
performed by a criminal” (Baase, 2012).
• Hacking activities such as release computer viruses,
stealing money and sensitive personal, business and
government information.
• The term has changed over time and has gone three
eras of hacking.
3
5.1 Hacking

• The three eras of hacking:


• Phase 1: The joy of programming
• Early 1960s to 1970s.
• It was a positive term.
• A "hacker" was a creative programmer who wrote elegant or
clever code.
• A "hack" was an especially clever piece of code.

4
5.1 Hacking

• The three eras of hacking:


• Phase 2: The rise of the hacking’s dark side
• From 1970s to mid 1990s.
• Breaking into computers for which the hacker does not have
authorized access.
• Still primarily individuals.
• Includes the spreading of computer worms and viruses and
‘phone phreaking’.
• Companies began using hackers to analyze and improve 5

security.
5.1 Hacking

• The three eras of hacking:


• Phase 3: The growth of the Web and mobile devices
• The growth of the Web changed hacking; viruses and worms could be
spread rapidly.
• Denial-of-service (DoS) attacks used to shut down Web sites.
• Large scale theft of personal and financial information.
• The “Love Bug” spread around the worlds in few hours, it infected
major corporations and destroyed image, music and operating systems
files. 6

• Sony sued George Hotz for showing how to run unauthorized


5.1 Hacking

• Hacking tools
• Some of the tools and types of malware (malicious software)
(Baase and Henry, 2018):
A. Virus
B. Worm
C. Trojan horse
D. Social engineering
E. Phishing
F. Pharming 7

G. Ransomware
H. Spyware
5.1 Hacking

• Is “harmless” hacking is harmless?


• When a business detects an intruder, they cannot
immediately distinguish a non-malicious hacker from a thief.
• At minimum, a business will spend time and effort to track
down the intruder, shut off the means of access, and
attempt to verify that the data not changed nor files were
stolen. 8

• The intruder can view sensitive data since if nothing was


5.1 Hacking

• Hackers as Security Researchers


• “White hat hackers” use their skills to demonstrate system
vulnerabilities and improve security.
• White hat hackers, for the most part, use their skills to
demonstrate system vulnerabilities and improve security.
• Security researcher hackers face ethical dilemmas, The most
obvious is: Is it ethical to break into a system without 9

permission, even with good intentions?


Hacking
Hacking as Foreign Policy
• Hacking governments has increased
• Pentagon has announced it would consider and treat
some cyber attacks as acts of war, and the U.S.
might respond with military force.
• How can we make critical systems safer from
attacks?

Corresponding page number: 239-240


5.1 Hacking

• Security
• A variety of factors contribute to security weaknesses:
1. History of the Internet and the Web:
• Early years, the Internet was primarily a communications medium for
researchers.
• The focus was on open access, ease of use, and ease of sharing
information.
• The Internet was not designed for security against malicious intruders.
2. Inherent complexity of computer systems 11

3. Speed at which new applications develop


Security
Hacking
• Internet started with open access as a means of sharing
information for research.

• Attitudes about security were slow to catch up with the


risks.

• Firewalls are used to monitor and filter out


communication from untrusted sites or that fit a profile
of suspicious activity.

• Security is often playing catch-up to hackers as new


vulnerabilities are discovered and exploited.
Corresponding page number: 241-244
5.1 Hacking

• Responsibility for security


• Developers have a responsibility to develop with security as
a goal.
• Businesses have a responsibility to use security tools and
monitor their systems to prevent attacks from succeeding.
• Home users have a responsibility to ask questions and
educate themselves on the tools to maintain security
(personal firewalls, anti-virus and anti-spyware).
13
Hacking

Discussion Questions
 Is hacking that does no direct damage a victimless
crime?
 Do you think hiring former hackers to enhance
security is a good idea or a bad idea? Why?

Corresponding page number: 230-245


5.1 Hacking

• The Law: Catching and Punishing Hackers-US.


• 1984 Congress passed the Computer Fraud and Abuse Act
(CFAA).
• Covers government computers, financial and medical systems, and
activities that involve computers in more than one state, including
15
computers connected to the Internet.
• Under CFAA, it is illegal to access a computer without
5.1 Hacking

• The Law: Catching and Punishing Hackers-KSA.


• 1428Anti-Cyber Crime Law (Bureau Of Experts At the
Council of Ministers, 2022)
• This Law aims to ensure (Bureau Of Experts At the Council
of Ministers, 2022):
1. Enhancing information security. 16

2. Protecting rights pertaining to the legitimate use of


Hacking

The Law: Catching and Punishing


Hackers
 Catching hackers
 Law enforcement agents read hacker newsletters and
participate in chat rooms undercover
 Security professionals set up ‘honey pots’ which are Web
sites that attract hackers, to record and study
 Computer forensics specialists can retrieve evidence from
computers, even if the user has deleted files and erased
the disks
 Investigators trace viruses and hacking attacks by using ISP
records and router logs
Corresponding page number: 246
5.1 Hacking

• The Law: Catching and Punishing Hackers-KSA.


• Examples of the cybercrimes and punishments can be
found on the Bureau Of Experts At the Council of
Ministers website.
• Link:
[Link]
18

73d6-0f49-4dc5-b010-a9a700f2ec1d/2
5.1 Hacking

• The Law: Catching and Punishing Hackers


• Criminalize virus writing and hacker tools?
• Several companies package large numbers of
viruses, malware and hacking tools for sale to 19

cybersecurity professionals to aid in security


Hacking
The Law: Catching and Punishing Hackers
 Expansion of the Computer Fraud and Abuse Act
 The CFAA predates social networks, smartphones, and
sophisticated invisible information gathering.
 Some prosecutors use the CFAA to bring charges against
people or businesses that do unauthorized data collection.
 Is violating terms of agreement a form of hacking?

Corresponding page number: 248-249


5.2 Identity Theft and Credit Card Fraud

• Identify theft describes “describes various


crimes in which a criminal (or large, well-
organized criminal group) uses the identity of
an unknowing innocent person” (Baase, 2012).
• Use credit/debit card numbers, personal information,
or use various other ways for financial gain.
• E-commerce has made it easier to steal and use card 21

numbers without having the physical card.


5.2 Identity Theft and Credit Card Fraud

• Techniques used to steal personal and financial


information:
1. Phishing - requests for personal and financial information
disguised as legitimate business communication.
2. Pharming – false Web sites that fish for personal and
financial information by planting false URLs, trying to lure
people to fake websites.
22
5.2 Identity Theft and Credit Card Fraud

• Responses to Identity Theft


1. Authentication of email and Web sites
2. Use of encryption to securely store data, so it is useless if
stolen
3. Authenticating customers to prevent use of stolen numbers,
may trade convenience for security
4. In the event information is stolen, a fraud alert can flag
your credit report; some businesses will cover the cost of a23
credit report if your information has been stolen
5.2 Identity Theft and Credit Card Fraud

• Responses to Identity Theft


5. Activation for new credit cards.
6. Retailers do not print the full card number and expiration
date on receipts.
7. Software detects unusual spending activities and will
prompt retailers to ask for identifying information.
8. Services, like PayPal, act as third party allowing a customer
to make a purchase without revealing their credit card 24

information to a stranger.
5.2 Identity Theft and Credit Card Fraud

• Biometrics
• Biometrics are “biological characteristics that are unique to
an individual” (Baase and Henry, 2018).
• Biometrics include fingerprints, voice print, face structure,
hand geometry, eye patters, and DNA.
• As any new technology, we must have an accurate view its
strength, weakness, and risks.
• Two main applications for biometrics, security and fraud 25

prevention.
5.3 Whose Laws Rule the Web

• Laws vary from country to country.


• Corporations that do business in multiple
countries must comply with the laws of all the
countries involved.
• Someone whose actions are legal in their own
country may face prosecution in another 26

country where their actions are illegal.


5.3 Whose Laws Rule the Web

• Solutions
• Responsibility-to-prevent-access
• Publishers must prevent material or services from
being accessed in countries where they are illegal.
• Authority-to-prevent entry
• Government of Country A can act within Country A 27

to try to block the entrance of material that is illegal


Reference List

• Sara Baase. A Gift of Fire: Social, Legal, and Ethical


Issues for Computing and the Internet, 4th Edition,
2012, Pearson.
• Sara Baase and Timothy M. Henry. A Gift of Fire: Social,
Legal, and Ethical Issues for Computing and the
Internet, 5th Edition, 2018, Pearson.
• Bureau Of Experts At the Council of Ministers 2022,
accessed
25/12/2022<[Link]
wDetails/25df73d6-0f49-4dc5-b010-a9a700f2ec1d/2< 28

You might also like