<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Confidential Resource &#187; Identity Theft</title>
	<atom:link href="http://www.confidentialresource.com/category/identity-theft/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.confidentialresource.com</link>
	<description>Sources &#38; Methods for the Investigator</description>
	<lastBuildDate>Fri, 10 Feb 2012 12:00:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Android Phone Security Risk</title>
		<link>http://www.confidentialresource.com/2011/05/17/android-phone-security-risk/</link>
		<comments>http://www.confidentialresource.com/2011/05/17/android-phone-security-risk/#comments</comments>
		<pubDate>Tue, 17 May 2011 15:28:57 +0000</pubDate>
		<dc:creator>Richard McEachin</dc:creator>
				<category><![CDATA[Communication]]></category>
		<category><![CDATA[Identity Fraud]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Android]]></category>

		<guid isPermaLink="false">http://www.confidentialresource.com/?p=2202</guid>
		<description><![CDATA[Android handsets &#8216;leak&#8217; personal data Many applications installed on Android phones interact with Google services by asking for an authentication token &#8230; Sometimes, found the researchers, these tokens are sent in plain text over wireless networks. This makes the tokens easy to spot&#8230; Armed with the token, criminals would be able to pose as a [...]]]></description>
			<content:encoded><![CDATA[<h2><a href="http://www.bbc.co.uk/news/technology-13422308" target="_blank">Android handsets &#8216;leak&#8217; personal data</a></h2>
<blockquote><p>Many applications installed on Android phones interact with Google  services by asking for an authentication token &#8230;</p>
<p>Sometimes, found the researchers, these tokens are sent in  plain text over wireless networks. This makes the tokens easy to spot&#8230;</p>
<p>Armed with the token, criminals would be able to pose as a particular user and get at their personal information.</p>
<p>Even worse, found the researchers, tokens are not bound to  particular phones or time of use so they can be used to impersonate a  handset almost anywhere.</p></blockquote>
<p>Now what might an unscrupulous person do with this? Might one be able to observe a person using his Android phone, capture the  token, then use it to find-out more about the person?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.confidentialresource.com/2011/05/17/android-phone-security-risk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Only in the U.S. &#8212; Pity</title>
		<link>http://www.confidentialresource.com/2011/03/17/only-in-the-u-s-pity/</link>
		<comments>http://www.confidentialresource.com/2011/03/17/only-in-the-u-s-pity/#comments</comments>
		<pubDate>Thu, 17 Mar 2011 15:06:34 +0000</pubDate>
		<dc:creator>Richard McEachin</dc:creator>
				<category><![CDATA[Fraud]]></category>
		<category><![CDATA[Identity Fraud]]></category>
		<category><![CDATA[Identity Theft]]></category>

		<guid isPermaLink="false">http://www.confidentialresource.com/?p=1920</guid>
		<description><![CDATA[The Identity Theft Evidence Trail In June 2004, the Cantwell/Enzi amendment of a federal bill called FACTA finally permitted ALL identity theft victims access to the credit applications and the transaction records in accounts opened fraudulently in their names. The reality is that once an account has been identified as fraudulent, the credit issuer must [...]]]></description>
			<content:encoded><![CDATA[<h2>T<a href="http://idtheftcenter.blogspot.com/2010/10/identity-theft-evidence-trail.html?spref=tw" target="_blank">he Identity Theft Evidence Trail</a></h2>
<blockquote><p>In June 2004, the Cantwell/Enzi amendment of a federal bill called FACTA finally permitted ALL identity theft victims access to the credit applications and the transaction records in accounts opened fraudulently in their names. The reality is that once an account has been identified as fraudulent, the credit issuer must provide application and transaction information to you and to the designated police, as long as you send a police report with your request. That law is FCRA section 609(e).&#8221;</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.confidentialresource.com/2011/03/17/only-in-the-u-s-pity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Disguises</title>
		<link>http://www.confidentialresource.com/2010/12/01/disguises/</link>
		<comments>http://www.confidentialresource.com/2010/12/01/disguises/#comments</comments>
		<pubDate>Wed, 01 Dec 2010 11:00:35 +0000</pubDate>
		<dc:creator>Richard McEachin</dc:creator>
				<category><![CDATA[Identity Fraud]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Private Investigator]]></category>
		<category><![CDATA[Surveillance]]></category>
		<category><![CDATA[Disguises]]></category>

		<guid isPermaLink="false">http://www.confidentialresource.com/?p=1302</guid>
		<description><![CDATA[Dyed hair and false beards are childish. Mere physical traits are of little use for identification. Context or &#8216;atmosphere&#8217; are what matters. If your subject gets into entirely different surroundings from those in which he was first observed &#8212; and this is the important part &#8212; really plays up to the new surroundings and behaves [...]]]></description>
			<content:encoded><![CDATA[<p>Dyed hair and false beards are childish. Mere physical traits are of little use for identification. Context or &#8216;atmosphere&#8217; are what matters.</p>
<p>If your subject gets into entirely different surroundings from those in which he was first observed &#8212; and this is the important part &#8212; really plays up to the new surroundings and behaves as if he had never been out of them, then he would be invisible to even the cleverest Private Investigator.</p>
<p>A fool tries to look different; a clever man looks the same and is, at the same time, different.</p>
<p>The deceiver assumes the new role by actually becoming the person he is impersonating. He is quietly absorbed into his new surroundings. In essence, the person you are seeking may be hiding in plain sight.</p>
<p><strong>In Plain Sight</strong></p>
<p>When he&#8217;s out and about near his Denver home, former Broncos quarterback John Elway has come up with a novel way to travel incognito—he wears his own jersey. &#8220;I do that all the time here,&#8221; the 50-year-old Hall of Famer told me. &#8220;I go to the mall that way. They know it&#8217;s not me because they say there&#8217;s no way Elway would be wearing his own jersey in the mall. So it actually is the safest thing to do.&#8221;  (Source: http://sportsillustrated.cnn.com/vault/article/magazine/MAG1175387/4/index.htm)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.confidentialresource.com/2010/12/01/disguises/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Detecting Firesheep</title>
		<link>http://www.confidentialresource.com/2010/11/29/detecting-firesheep/</link>
		<comments>http://www.confidentialresource.com/2010/11/29/detecting-firesheep/#comments</comments>
		<pubDate>Mon, 29 Nov 2010 11:00:35 +0000</pubDate>
		<dc:creator>Richard McEachin</dc:creator>
				<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Methods]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Sites]]></category>
		<category><![CDATA[Surveillance]]></category>
		<category><![CDATA[The Investigator's Computer]]></category>
		<category><![CDATA[Firesheep]]></category>

		<guid isPermaLink="false">http://www.confidentialresource.com/?p=1288</guid>
		<description><![CDATA[I wrote about Firesheep awhile back. Predictably, a countermeasure has appeared called Blacksheep. New Firefox Add-On Detects Firesheep, Protects You on Open Networks If you’re concerned about using open Wi-Fi networks because of Firesheep, the highly popular new hacking tool, you should check out BlackSheep, a Firefox add-on that makes surfing on open networks safe [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.confidentialresource.com/2010/11/08/hijacking-social-network-connections/" target="_blank">I wrote about Firesheep awhile back</a>. Predictably, a countermeasure has appeared called <a href="http://www.zscaler.com/blacksheep.html" target="_blank">Blacksheep</a>.</p>
<h2><a href="http://mashable.com/2010/11/08/firesheep-protection/" target="_blank">New Firefox Add-On Detects Firesheep, Protects You on Open Networks</a></h2>
<blockquote><p>If you’re concerned about using open Wi-Fi networks because of <a href="http://mashable.com/tag/firesheep/" target="_blank">Firesheep</a>, the highly popular new hacking tool, you should check out BlackSheep, a Firefox add-on that makes surfing on open networks safe once again.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.confidentialresource.com/2010/11/29/detecting-firesheep/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PI&#8217;s Hired to Dumpster Dive</title>
		<link>http://www.confidentialresource.com/2010/11/09/1230/</link>
		<comments>http://www.confidentialresource.com/2010/11/09/1230/#comments</comments>
		<pubDate>Tue, 09 Nov 2010 22:06:02 +0000</pubDate>
		<dc:creator>Richard McEachin</dc:creator>
				<category><![CDATA[Canada]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Private Investigator]]></category>

		<guid isPermaLink="false">http://www.confidentialresource.com/?p=1230</guid>
		<description><![CDATA[Personal data at risk, study found Some doctors’ offices and car dealers in the Greater Toronto Area got a failing grade after private investigators found easily accessible personal records in their dumpsters.]]></description>
			<content:encoded><![CDATA[<h2><a href="http://www.thestar.com/business/smartmoney/article/882616--personal-data-at-risk-study-found" target="_blank">Personal data at risk, study found</a></h2>
<blockquote><p>Some doctors’ offices and car dealers in the Greater Toronto Area got a failing grade after private investigators found easily accessible personal records in their dumpsters.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.confidentialresource.com/2010/11/09/1230/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hijacking Social Network Connections</title>
		<link>http://www.confidentialresource.com/2010/11/08/hijacking-social-network-connections/</link>
		<comments>http://www.confidentialresource.com/2010/11/08/hijacking-social-network-connections/#comments</comments>
		<pubDate>Mon, 08 Nov 2010 11:00:44 +0000</pubDate>
		<dc:creator>Richard McEachin</dc:creator>
				<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Methods]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Sites]]></category>
		<category><![CDATA[Surveillance]]></category>
		<category><![CDATA[The Investigator's Computer]]></category>
		<category><![CDATA[Firesheep]]></category>

		<guid isPermaLink="false">http://www.confidentialresource.com/?p=1130</guid>
		<description><![CDATA[The Firesheep Firefox plugin makes it easy to hijack someone&#8217;s social network connections. For example, Facebook authenticates the client using cookies. If someone logs on using a public WiFi connection, the cookies are sniffable. Firesheep uses Wincap to capture the authentication information which allows you to hijack the connection. Protect yourself by forcing the authentication [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://codebutler.github.com/firesheep/" target="_blank">Firesheep</a> Firefox plugin makes it easy to hijack someone&#8217;s social network connections. For example, Facebook authenticates the client using cookies. If someone logs on using a public WiFi connection, the cookies are sniffable. Firesheep uses <a href="http://www.winpcap.org/install/default.htm" target="_blank">Wincap</a> to capture the authentication information which allows you to hijack the connection.</p>
<p><a href="http://techcrunch.com/2010/10/25/firesheep/" target="_blank">Protect yourself</a> by forcing the authentication through <a href="http://en.wikipedia.org/wiki/Transport_Layer_Security" target="_blank">TLS</a> or stop logging into Facebook using public networks.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.confidentialresource.com/2010/11/08/hijacking-social-network-connections/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>UK to Axe Identity Card Scheme</title>
		<link>http://www.confidentialresource.com/2010/06/01/uk-to-axe-identity-card-scheme/</link>
		<comments>http://www.confidentialresource.com/2010/06/01/uk-to-axe-identity-card-scheme/#comments</comments>
		<pubDate>Tue, 01 Jun 2010 20:06:08 +0000</pubDate>
		<dc:creator>Richard McEachin</dc:creator>
				<category><![CDATA[Identity Fraud]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[United Kingdom]]></category>

		<guid isPermaLink="false">http://www.confidentialresource.com/2010/06/01/uk-to-axe-identity-card-scheme/</guid>
		<description><![CDATA[National identity card schemes usually end badly for somebody, usually the average citizen. These overpriced schemes usually assist death-by-government programmes or become one point of failure that usually fails through corruption and/or criminal action. Identity cards scheme will be axed &#8216;within 100 days&#8217; The National Identity Card scheme will be abolished within 100 days with [...]]]></description>
			<content:encoded><![CDATA[<p>National identity card schemes usually end badly for somebody, usually the average citizen. These overpriced schemes usually assist death-by-government programmes or become one point of failure that usually fails through corruption and/or criminal action.</p>
<h2><a href="http://news.bbc.co.uk/2/hi/uk_news/politics/8707355.stm" target="_blank">Identity cards scheme will be axed &#8216;within 100 days&#8217;</a></h2>
<blockquote><p>The National Identity Card scheme will be abolished within 100 days with all cards becoming invalid, Home Secretary Theresa May has said.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.confidentialresource.com/2010/06/01/uk-to-axe-identity-card-scheme/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Evidence of a Person&#8217;s Identity</title>
		<link>http://www.confidentialresource.com/2010/04/30/evidence-of-a-persons-identity/</link>
		<comments>http://www.confidentialresource.com/2010/04/30/evidence-of-a-persons-identity/#comments</comments>
		<pubDate>Fri, 30 Apr 2010 11:00:34 +0000</pubDate>
		<dc:creator>Richard McEachin</dc:creator>
				<category><![CDATA[Identity Fraud]]></category>
		<category><![CDATA[Identity Theft]]></category>

		<guid isPermaLink="false">http://www.confidentialresource.com/2010/04/30/evidence-of-a-persons-identity/</guid>
		<description><![CDATA[Question #10 is, &#8220;What evidence do you have that this is all true?&#8221; Identity documents and what the person in question tells you are not sound evidence of a person&#8217;s identity. A person&#8217;s identity is  rooted in their life &#8212; where they have lived, worked, gone to school, their relatives and friends. Countries that have [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.confidentialresource.com/2010/03/15/identity/" target="_blank">Question #10</a> is, &#8220;What evidence do you have that this is all true?&#8221;</p>
<p>Identity documents and what the person in question tells you are not sound evidence of a person&#8217;s identity. A person&#8217;s identity is  rooted in their life &#8212; where they have lived, worked, gone to school, their relatives and friends.</p>
<p>Countries that have a national identity card system run the risk of the identity card becoming  the single point of failure by making the card the only source of identity information. When this happens, the crook can hide behind the card produced by a compromised system.</p>
<p>If you are in a position that requires you to test claims of identity, then you have to dig deeper for supporting documentation and verification.</p>
<p>The best place to start digging is the persons employment. This may be faked by providing fake companies with phone numbers that are answered by confederates. Check for the  existence of the firms before contacting them. A good place to start is to Google the firm&#8217;s phone number to see if appears associated with the firm and nothing else.</p>
<p>For current residence ask for utility bills and home insurance policies. A faker may have a utility bill but they rarely pay for a fake home insurance policy.</p>
<p>When checking references, always ask for the names and contact details of the subject&#8217;s friends and family. Of course, you rarely get this, but you may get  useful corroborating data, or you may learn that these people don&#8217;t really know the subject if they do not know any of his friends or family.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.confidentialresource.com/2010/04/30/evidence-of-a-persons-identity/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The Passport</title>
		<link>http://www.confidentialresource.com/2010/04/19/the-passport/</link>
		<comments>http://www.confidentialresource.com/2010/04/19/the-passport/#comments</comments>
		<pubDate>Mon, 19 Apr 2010 11:00:40 +0000</pubDate>
		<dc:creator>Richard McEachin</dc:creator>
				<category><![CDATA[Identity Fraud]]></category>
		<category><![CDATA[Identity Theft]]></category>

		<guid isPermaLink="false">http://www.confidentialresource.com/2010/04/19/the-passport/</guid>
		<description><![CDATA[Questions #8 and #9 are, &#8220;What is your passport number?&#8221; and &#8220;Where was it issued?&#8221; Most people regard a passport as the most reliable and secure identity document. However, this is far from the truth of the matter. For example, Citizenship and  Immigration Canada does not accept certain travel documents because they are easily forged [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.confidentialresource.com/2010/03/15/identity/" target="_blank">Questions #8 and #9 </a>are, &#8220;What is your passport number?&#8221; and &#8220;Where was it issued?&#8221;</p>
<p>Most people regard a passport as the most reliable and secure identity document. However, this is far from the truth of the matter. For example, <a href="http://www.cic.gc.ca/english/visit/apply-who.asp" target="_blank">Citizenship and  Immigration Canada does not accept certain travel documents</a> because they are easily forged or obtained through fraud.</p>
<blockquote>
<p class="box-dashed">On March 11, 2010, <acronym title="Citizenship and Immigration Canada">CIC</acronym>  amended the <em>Immigration and Refugee Protection Regulations</em> to clarify the factors used to determine which travel documents can be used to apply for a visa, and to travel to or enter Canada.</p>
<p>Under the new Regulations, the following travel documents are considered unreliable and are not acceptable for entry into Canada:</p>
<ul>
<li>any passport claiming to have been issued by Somalia,</li>
<li>non-machine readable passports issued by the Czech Republic,</li>
<li>temporary passports issued by the Republic of South Africa, and</li>
<li>provisional passports issued by Venezuela.</li>
</ul>
</blockquote>
<p>We have not found any way to link a passport number to the issuing country and the person named in it. Nor, have we found a reliable source of information about how to recognise a forged passport. This makes relying on such a document without expert knowledge and the resources of a government department unwise.</p>
<p>If the current passport was issued through an embassy outside the country of residence, then you may have reason to investigate further. Also, remember, it is easier to make yourself look like the person pictured in the passport than it is to forge the passport. If you have any doubt that the person in the passport is the person before you, then action must be taken.</p>
<blockquote></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.confidentialresource.com/2010/04/19/the-passport/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Phone Numbers and Identity</title>
		<link>http://www.confidentialresource.com/2010/04/12/phone-numbers-and-identity/</link>
		<comments>http://www.confidentialresource.com/2010/04/12/phone-numbers-and-identity/#comments</comments>
		<pubDate>Mon, 12 Apr 2010 11:00:54 +0000</pubDate>
		<dc:creator>Richard McEachin</dc:creator>
				<category><![CDATA[Identity Fraud]]></category>
		<category><![CDATA[Identity Theft]]></category>

		<guid isPermaLink="false">http://www.confidentialresource.com/2010/04/12/phone-numbers-and-identity/</guid>
		<description><![CDATA[Question #7 is, &#8220;What are your phone numbers?&#8221; I always ask for home, work, fax, and mobile numbers.  I always Google these numbers and search them in D&#38;B and other databases with a telephone number field. It is amazing what turns-up when you do this. For example, dozens of businesses using the same fax number, [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.confidentialresource.com/2010/03/15/identity/" target="_blank">Question #7</a> is, &#8220;What are your phone numbers?&#8221;</p>
<p>I always ask for home, work, fax, and mobile numbers.  I always Google these numbers and search them in D&amp;B and other databases with a telephone number field. It is amazing what turns-up when you do this. For example, dozens of businesses using the same fax number, or prostitution ads using the same number. Things like this have to be investigated.</p>
<p>I recently found a subject&#8217;s mobile phone number on eBay where he was selling goods from his former employer who found this very odd, but the police didn&#8217;t &#8212; they charged him with a series of thefts.</p>
<p>Email addresses should be treated in the same manner but also <a href="http://www.confidentialresource.com/2008/10/08/finding-usernames/" target="_blank">search for usernames and social sites</a> associated with the subject.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.confidentialresource.com/2010/04/12/phone-numbers-and-identity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

