SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Security Products, Practices and Infrastructure

Software designed to prevent identity theft

Software designed to prevent identity theft

By:  Kathleen Lau  On: 13 Feb 2008 For: ComputerWorld Canada Creator

Identity Finder works by searching systems for cookies, IM logs and other files for confidential personal information. An analyst says it may not be enterprise class but does help plug some holes

Using peer-to-peer (P2P) file sharing applications on the job raises the risk that confidential data residing on a user’s PC might be inadvertently exposed to a cybercriminal, said the head of a security vendor.

It’s tricky to prevent employees from using P2P applications at work, and besides, imposing a corporate policy to prevent them from using these networks is not necessarily the best approach, said Todd Feinman, CEO of New York City-based security technology provider Identity Finder, a division of Velosecure LLC.

Another useful policy is for employees to be aware of what actually lives on their systems, said Feinman.

“These employees don’t realize that such sensitive information exists in their files,” he said, adding that if the threat doesn’t stem from P2P applications then it’ll surely be from another.

Feinman said the enterprise edition of the company’s security software, Identity Finder, is intended to help businesses search and secure confidential data residing on user systems, like employee identifications, telephone numbers, passwords/PINs, dates of birth, and Social Insurance Numbers.

It works by automatically trolling a user’s computer system in places like a Web browser’s auto-complete fields, Web pages and cookies, instant messenger logs and compressed files. The software can be customized to identify certain types of data, and the process doesn’t require users to enter specific information about themselves, the company, or a customer.

Once done, the user receives a report as a means to preview the action to be applied to the identified data.

Feinman said employees can use the software on individual systems, or IT administrators can apply the tool on the back end, by way of admin privileges, to scan file systems or e-mail clients of remote network computers. “[The latter is] a good approach because having all that information in one place allows you to run a report and say, ‘Here’s how much we’re at risk.’”

However, he cautioned the sole downside to the backend approach is the inability on the part of the IT admin to take action on identified data. In this instance, IT can use the quarantine function to move data to a central server in case it needs to be restored to the user.

More often, though, Feinman observed IT admins including it as an extra feature on builds and computer images so employees can run it on a regular basis, while IT supports it.

Feinman suggests the following security process around Identity Finder: deploy the software, push it out to employees, customize it to individual needs, set a regular schedule to run a system search, and set pop-up reminders for action to be taken on identified data.


Sign up for our Newsletters












Print |  Views: 1089   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Kathleen Lau Kathleen Lau was a senior writer with ITWorldCanada.com and ComputerWorld Canada from December 2006 to August 2011.In her role as senior writer, she covered broadly technology news and issues r... more

Related Content

Controlling 'shadow IT'
Controlling 'shadow IT'Some see it as grassroots deployment of cool technologies; some see it as weeds growing from any crack in the IT plan
InterGovWorld.com community blogs
InterGovWorld.com community blogsInterGovWorld.com readers write back
Beware the pod people
Beware the pod peopleAre iPods really as innocent as they seem? Some believe that they pose a significant security risk to the organization. Here’s what you can do about it.
The telephone: The original social networking tool
i would have thought senior technology executives had had enough of all the social networking talk but “enabling communities” was the focus of discussion at a meeting this evening of the cio association of canada’s ontario chapter. as it turned out, it was an audience member, and not a presenter, who made a point that got me thinking.unfortunately i couldn’t stay for the entire eve

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.