State of Oklahoma

Monthly Cyber Security Tips
NEWSLETTER

 

 JULY 2006

Volume 1, Issue 2

How Anonymous Are You?

From the Desk of CPT Jeff Elliott, Oklahoma Office of Homeland Security, Oklahoma Highway Patrol

What information is collected?

When you visit a web site, a certain amount of information is automatically sent to the site. This information may include the following:

If a web site uses cookies, the organization may be able to collect even more information, such as your browsing patterns, which include other sites you've visited. If the site you're vising is malicious, files on your computer, as well as passwords stored in the temporary memory, may be at risk.

How is this information used?

Generally, organizations use the information that is gathered automatically for legitimate purposes, such as generating statistics about their sites. By analyzing the statistics, the organizations can better understand the popularity of the site and which areas of content are being accessed the most. They may be able to use this information to modify the site to better support the behavior of the people visiting it.

Another way to apply information gathered about users is marketing. If the site uses cookies to determine other sites or pages you have visited, it may use this information to advertise certain products. The products may be on the same site or may be offered by partner sites.

However, some sites may collect your information for malicious purposes. If attackers are able to access files, passwords, or personal information on your computer, they may be able to use this data to their advantage. The attackers may be able to steal your identity, using and abusing your personal information for financial gain. A common practice is for attackers to use this type of information once or twice, then sell or trade it to other people. The attackers profit from the sale or trade, and increasing the number of transactions makes it more difficult to trace any activity back to them. The attackers may also alter the security settings on your computer so that they can access and use your computer for other malicious activity.

Are you exposing any other personal information?

While using cookies may be one method for gathering information, the easiest way for attackers to get access to personal information is to ask for it. By representing a malicious site as a legitimate one, attackers may be able to convince you to give them your address, credit card information, social security number, or other personal data (see Avoiding Social Engineering and Phishing Attacks for more information).

How can you limit the amount of information collected about you?

 

 

 

This series of information security tips will give you more information about how to recognize and protect yourself from attacks.

 

Brought to you by:

MS-ISAC logo   http://www.msisac.org

Powered

 by:

 


Copyright Carnegie Mellon University
Produced byUS-CERT  http://www.us-cert.gov/