Thursday, August 09, 2007

Have you been Compromised?

I was reading Michael Dahn's blog, and saw a link to where you can type in credential information and find out if you (or your identity) have been bought & sold lately.

My devil's advocate came out (I'm a security guy at heart) and reared its head and immediately thought - if I set up a similar site, register a few domain names with some misspellings or use meta data from the legit site, I could in fact set up a very simple identity data capture site, claim it's more secure than Stolen ID Search because I require more information (like a CC#, zip code, etc.) and guess what - I'm in business as an identity thief. If someone stole this idea let me know, it's not that hard...


