<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Mobile Security &#187; CNP</title>
	<atom:link href="http://blog.m-sec.net/tag/cnp/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.m-sec.net</link>
	<description>When security is not enough</description>
	<lastBuildDate>Tue, 13 Nov 2012 20:58:39 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.2</generator>
		<item>
		<title>About privacy and data protection (II)</title>
		<link>http://blog.m-sec.net/2011/about-privacy-and-data-protection-ii/</link>
		<comments>http://blog.m-sec.net/2011/about-privacy-and-data-protection-ii/#comments</comments>
		<pubDate>Sat, 06 Aug 2011 22:16:05 +0000</pubDate>
		<dc:creator>m-sec.net</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[bank]]></category>
		<category><![CDATA[CNP]]></category>
		<category><![CDATA[crack]]></category>
		<category><![CDATA[iban]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[SSN]]></category>

		<guid isPermaLink="false">http://blog.m-sec.net/?p=37</guid>
		<description><![CDATA[As stated in my previous post, there are other legal ways you can find some special private data about someone else. 1. You call yourself &#8220;Carrefour&#8220;, you put up a marketing campaign and ask your customers to fill in a form where one of the fields is the Numerical Personal Code. Of course, you are [...]]]></description>
			<content:encoded><![CDATA[<p>As stated in my previous post, there are other legal ways you can find some special private data about someone else.</p>
<p>1. You call yourself &#8220;<em>Carrefour</em>&#8220;, you put up a marketing campaign and ask your customers to fill in a form where one of the fields is the <a title="CNP Romania" href="http://en.wikipedia.org/wiki/Romanian_identity_card" target="_blank">Numerical Personal Code</a>. Of course, you are not registered as a company who deals with private data (according to <a title="Data protection Romania" href="http://www.dataprotection.ro/" target="_blank">ANSPDCP</a>&#8216;s website). There are a lot of people out there that give their personal information just to get 10$.  I really wonder if it was to give their credit card info and PIN, would they really give it?</p>
<p>2. What about if you are <em>a bank</em>? Or a customer of a bank? Theoretically your private details like bank account, <a title="Romanian CNP" href="http://en.wikipedia.org/wiki/Romanian_identity_card" target="_blank">CNP</a>, address, etc should be safe. Well&#8230;that&#8217;s the theory. There is one bank out there (you&#8217;ll discover the name below) that allows you to find protected info about any of its customers. Let&#8217;s say you have an i-banking account with them and you get the <a title="IBAN details" href="http://en.wikipedia.org/wiki/International_Bank_Account_Number" target="_blank">IBAN</a> account of one of their customers. As soon as you try to make a money transfer to that person, you will get that person&#8217;s name. What&#8217;s wrong with that you will say. Well, you can just play around with the IBAN account and discover other valid accounts along with the holder&#8217;s name. Ok, I agree, maybe that&#8217;s not a serious security problem. Once you continue with the money transfer, you can see more: in the details of the transfer <strong>you also get the CNP of that someone</strong>. And yes, the bank is registered as a private company who deals with confidential data and obeys the law. Right!</p>
<p>See a demo for yourself. I have blurred some details, but that&#8217;s the only edit on the video.<br />
<iframe src="http://player.vimeo.com/video/27367161?title=0&amp;byline=0&amp;portrait=0" frameborder="0" width="500" height="400"></iframe></p>
<div id="tweetbutton37" class="tw_button" style=""><a href="http://twitter.com/share?url=http%3A%2F%2Fblog.m-sec.net%2F2011%2Fabout-privacy-and-data-protection-ii%2F&amp;via=msecnet&amp;text=About%20privacy%20and%20data%20protection%20%28II%29&amp;related=&amp;lang=en&amp;count=horizontal&amp;counturl=http%3A%2F%2Fblog.m-sec.net%2F2011%2Fabout-privacy-and-data-protection-ii%2F" class="twitter-share-button"  style="width:55px;height:22px;background:transparent url('http://blog.m-sec.net/wp-content/plugins/wp-tweet-button/tweetn.png') no-repeat  0 0;text-align:left;text-indent:-9999px;display:block;">Tweet</a></div>]]></content:encoded>
			<wfw:commentRss>http://blog.m-sec.net/2011/about-privacy-and-data-protection-ii/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>About privacy and data protection (I)</title>
		<link>http://blog.m-sec.net/2011/about-privacy-and-data-protection-i/</link>
		<comments>http://blog.m-sec.net/2011/about-privacy-and-data-protection-i/#comments</comments>
		<pubDate>Mon, 25 Jul 2011 19:39:35 +0000</pubDate>
		<dc:creator>m-sec.net</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[CNP]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[PIN]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[SSN]]></category>

		<guid isPermaLink="false">http://blog.m-sec.net/?p=24</guid>
		<description><![CDATA[Today I&#8217;m going to start a topic about privacy. Even though I&#8217;ll write about some experiences I had in Romania, I&#8217;m pretty sure this can be applied to other countries too. The main subject will be about how hard is to find someone&#8217;s Numerical Personal Code (how it&#8217;s called in Romania) or Social Security Number [...]]]></description>
			<content:encoded><![CDATA[<p>Today I&#8217;m going to start a topic about privacy. Even though I&#8217;ll write about some experiences I had in Romania, I&#8217;m pretty sure this can be applied to other countries too. The main subject will be about how hard is to find someone&#8217;s <a title="CNP" href="http://en.wikipedia.org/wiki/National_identification_number#Romania" target="_blank">Numerical Personal Code</a> (how it&#8217;s called in Romania) or Social Security Number in US.</p>
<p>A few months ago I was googleing a friend&#8217;s name in order to find his email address. While searching I got to <a title="Vrajitorul" href="http://www.vrajitorul.eu" target="_blank">a website</a> which showed his address and telephone number. I was pretty surprised to see that and since the website had a search engine, I started to look for different persons &#8211; for some I got results. This was looking more and more interesting. I notice that there was also possible to create a test account with some free credits and with more search results. After waiting a day or so I finally got my account. Now the information I could find was astonishing. Not only I got the address and the phone, but also the Numerical Personal Code, what bank loans did they have (if any), how much they got ad so on.</p>

<a href="http://blog.m-sec.net/wp-content/uploads/2011/07/vrajitorul_CNP1.png" title="" class="shutterset_singlepic15" >
	<img class="ngg-singlepic" src="http://blog.m-sec.net/wp-content/gallery/cache/15__320x240_vrajitorul_CNP1.png" alt="vrajitorul_CNP1" title="vrajitorul_CNP1" />
</a>

<p>As you can see all the information is there. For privacy reasons I have hidden the data. But from where such a website could get all that information? Is there someone freely submitting the information? The response came quickly:</p>

<a href="http://blog.m-sec.net/wp-content/uploads/2011/07/vrajitorul_datasource.png" title="" class="shutterset_singlepic18" >
	<img class="ngg-singlepic" src="http://blog.m-sec.net/wp-content/gallery/cache/18__320x240_vrajitorul_datasource.png" alt="vrajitorul_datasource" title="vrajitorul_datasource" />
</a>

<p>I was WOW-ed. So <strong>our own government</strong> is publishing all these information to the public? What about data protection? What about privacy? It was kind of hard to believe, but after searching some published papers by the Romanian&#8217;s Official Journal I convinced myself of the reality.</p>

<a href="http://blog.m-sec.net/wp-content/uploads/2011/07/CNP_MOF.png" title="" class="shutterset_singlepic3" >
	<img class="ngg-singlepic" src="http://blog.m-sec.net/wp-content/gallery/cache/3__320x240_CNP_MOF.png" alt="CNP_MOF" title="CNP_MOF" />
</a>

<p>After accessing the <strong>official published paper</strong> I could also find: <strong><em>address, the date when the ID card was issued, the issuer name, ID number, Numerical Personal Code</em></strong>. If this is published freely by the government, then what else could I ask to a private company? Luckily, I knew that there is also an agency which is taking care of such issues &#8211; <a title="ANSPDPC" href="http://www.dataprotection.ro/" target="_blank">ANSPDCP</a> (hard to translate <img src='http://blog.m-sec.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ). However, how could I contact the agency (which is controlled by the government) and ask them to remove such information?</p>
<p>All that Vrajitorul website does is to get this information and structure it in a way that you can easily find. <strong>BUT</strong> there is hope. In case your personal identification info is somewhere on a website, you can contact the owner of the website and kindly ask to remove all this information as they are breaking the <a title="Data protection law Romania" href="http://www.legi-internet.ro/legislatie-itc/date-cu-caracter-personal/legea-privind-prelucrarea-datelor-cu-caracter-personal-si-protectia-vietii-private-in-sectorul-comunicatiilor-electronice.html" target="_blank">personal data protection law</a> and in case they will not do so, you will contact the ANSPDCP agency. My friend did this and all the data that the website had about him was removed the next day. I strongly suggest you to do the same.</p>
<p>Comments? Next time I&#8217;ll write about some private companies (including a bank) which have problems in protecting sensitive information about their customers.</p>
<p>&nbsp;</p>
<div id="tweetbutton24" class="tw_button" style=""><a href="http://twitter.com/share?url=http%3A%2F%2Fblog.m-sec.net%2F2011%2Fabout-privacy-and-data-protection-i%2F&amp;via=msecnet&amp;text=About%20privacy%20and%20data%20protection%20%28I%29&amp;related=&amp;lang=en&amp;count=horizontal&amp;counturl=http%3A%2F%2Fblog.m-sec.net%2F2011%2Fabout-privacy-and-data-protection-i%2F" class="twitter-share-button"  style="width:55px;height:22px;background:transparent url('http://blog.m-sec.net/wp-content/plugins/wp-tweet-button/tweetn.png') no-repeat  0 0;text-align:left;text-indent:-9999px;display:block;">Tweet</a></div>]]></content:encoded>
			<wfw:commentRss>http://blog.m-sec.net/2011/about-privacy-and-data-protection-i/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
