Sunday, February 8, 2009

The application of 3rd party certification programme in Malaysia.

Internet users may fear whether personal data that they provide in the internet are safe and not stolen by others. Most of the public organizations have imposed internet security onto their internet web page. These internet securities basically guarantee four essential components in establishing trust on-line and smart card based transactions, and they are: confidentiality, authentication, integrity and non-repudiation.


At present the licensed Certification Authorities which can issue out digital certificates are Digicert Sdn Bhd and MSC Trustgate Dotcom Sdn Bhd. Both companies offer certification services with digital certificates to secure web servers, browser and email packages with a range of assurance level.


Besides, Malaysian Communications and Multimedia Commission have played a role where it oversees and regulates the operations of the Certification Authorities, repositories and date/time stamping services in Malaysia. Apart from that, it is also empowered to ensure that the licensed Certification Authorities and the recognized repositories and date/time service providers maintain a high level of integrity and quality in rendering their services. It also looks into the determination and coordination of the Certification Authority trust model and cross-certification policies with foreign Certification Authorities.

With the 3rd party certification programme in Malaysia, we will be able to transact on the internet without fear of having our personal data stolen, our information contaminated by third parties, and our transacting party denying any commercial commitment with us. Furthermore, it assists in the development of greater Internet based activities.  

How to safeguard our personal and financial data?

Nowadays the number of crime on stealing personal and financial data from outsider is increased. We should put more attention on how to safeguard our own personal and financial data from outsider. It is very dangerous for us to disclose our personal data in the internet. For those users who want disclose some of his or her personal data in internet he or she can subscribe anti virus software such as Crypto Heaven to safeguard the file. Crypto Heaven allow us to send encrypted email, share file such as picture and business document and securely backup in secure environment. Beside that there is others way to safeguard our data so that the hackers not able to access our personal and financial data.

Here is some way that we can safeguard our personal data,

We can use strong password. What kind of password we call it as strong password? A strong password is more that 12 words and it include Digit (0-9), Alphabetic (A-Z), and also some of the special character (@,#,^,<,>,$). Besides that the password that you set is hard to get from dictionary. For example: 10y@o$h3ng1987. Passwords such as Dog, 123456 or yys19 are not recommended to use. By having strong password hackers is not easy or not able to access our personal and financial data easily.

Besides that we can have Credit Card Holder can subscribe paypal to secure his or her Credit Card Number. It is because when we buy things from internet the seller charge us by have Credit Card Transaction, so we need to give them out credit card number so he or she can have transaction toward us. Paypal can secure the Credit Card Holder by having the transaction with the seller without giving out credit card number to the seller. 

Here is some others suggestion,

·      Avoid clicking on pop-up ads or downloading information from unknown sites.

·      Use your own computer, instead of a work or public machine, to access financial and other sensitive personal information.

·      Avoid giving your personal information to “cold callers” and other unknown parties online, via e-mail and over the phone.

·      Resist using free wireless connections — particularly in cafes, airports and other public places — to check personal information.

·      Use and update antivirus and antispyware software

This is my opinion to secure your personal and financial data. Well there will be others solution more to secure our personal and financial.

The threat of online security: How safe is our data?

Internet such as online shopping, online banking, communicating with overseas friends and others activities are becoming part of our life no matter for young peoples or old peoples. So, online security is important for all Internet users because Internet is not a safe place unless an adequate security against different types of threats that exist in cyberspace. 

There are 3 categories of cyber attacks:                

(1)  Accidental actions cover problems arising from basic lack of knowledge about online security concepts. Moreover, issues such as unintentional or erroneous business transactions, poor password choices, erroneous or outdated software, and unintentional disclosure are also included in accidental actions. It contributes to a large number of computer security risks.

 

(2)  Online fraud is also known as cyber vulnerability. It is a broad term covering Internet transactions that involve falsified information. The newest form of scheme that has been viewed in traditional settings for many years is personal identity theft on the Internet. Some most common forms of online fraud are the sale through Internet of counterfeit documents such as diplomas and recommendation letters sold as credentials. In the Internet world, electronic commerce information can be captured as a result of vulnerabilities in computer precautions.

 

(3)  Malicious attacks are attacks that particularly aimed to do harm and are known as premeditated. The typical malicious attacks are virus, worm, Trojan horse and rookit. Examples for malicious attacks are data theft and Denial of Service (DOS). Denial of service attacks is another form of malicious code and are carefully crafted, executed. DOS crash computers or issue floods of commands to overwhelm websites to steal personal information, such as credit-card and bank numbers. DOS are not fresh but they are rising in difficulty.


Security Tips

-        Install a firewall which is software that runs on another computer. Protective barriers between your computer and potential harmful attacks can create by firewall. Some more, it inspects network traffic passing through it and denies or allows passage based on a set of rules.    

-       Use one of the antivirus and antispyware programs on the market. This software protects against viruses and malicious code that come through email and other else. Good anti-virus software will automatically update itself on a regular basis and they can recognize the new threats.                                                

-       Pay attention to the messages from Windows that pop up on your screen, especially in the new Vista operating system.

-       Don’t click on any links in social network messages from people that you don’t know.

-       Keep security and system patches up to date.

-       Choose your computer passwords wisely.

-       Turn on Windows’ automatic- update function to get Microsoft’s regular security patches. 






Phishing: Examples and its prevention methods

Phishing is the criminally fraudulent process of attempting to acquire important information such as usernames, passwords and credit card details. For example, the hacker/cracker will send e-mail or instant message ask users to update their personal information such as credit card number and bank account number.

Example of phising 

Sample 1: Look like a message from eBay's payment system PayPal.


Figure 1.1 Example receipt of Ebay – Paypal

 

When the users click on the link, the users are re-directed to sample 2. At the sample 1 looks like the PayPal website, but when the users check the address at the top the users will see that the people who want users email address and PayPal password are hiding behind some obscure site.

Sample 2: Look like a message from eBay's payment system PayPal.


Some prevention methods for phishing

  1. While the users receive any email from the bank ask users verify their account information, and then the users must check the sender of the email. When the email address is not the domain of a legitimate bank, then it is certain that email is a phishing.
  2. The users do not follow a click here link in the email. The phishing emails usually have a ‘Click here to re-enter user information’ kind of link that leads to an illegitimate website.
  3. The users must check contract information provided in the email. It is because have a lot of phishing emails contain fake contract information that would just serve users into their hands.
  4. The users must check the information about users provided in the email. Hacker/cracker is getting better and better at obtaining users information.

Tuesday, January 27, 2009

The history and evolution of E-commerce

Nowadays, internet has changed the way that we buying and selling goods or services. We can make business transactions online on such a regular basic such as online banking and online booking for hotel rooms as well. This action of buying and selling goods or services through the internet is called “E-commerce”. E-commerce is not just about buying and selling, it is also about electronically collaborating, communicating, and discovering information which sometimes also referred as e-business. It is about e-learning, e-government, social networks and others else.

In the early 1970s, development of e-commerce applications set up with electronic funds transfer (EFT) which transfers of funds between accounts by electronic such as Automatic Teller Machines (ATM). Electronic data interchange (EDI) was developed in the late of 1970s to improve the limitation of EFT. It is a set of standards developed in the 1960’s to exchange business information and do electronic transactions.

When the United States government allowed public to access to the internet in 1991, there was a significant change for e-commerce. Online retail products were offers by CompuServe to its consumer and this gives people the first opportunity to buy things online. E-commerce started to become famous during 1994 and it took four years for it to build the security protocols and DSL which permit rapid access and connection to the internet.

E-commerce shifted from business-to-consumer to business-to-business in 1999 and change from business-to-business to business-to-exchange in 2001. The 5 largest and most popular world wide internet retailers are Amazon, Dell, Staples, Office Depot and Hewlett Packard. E-commerce is one of the leading forces of economic growth today. It bring many benefits to users, suppliers and consumers such as saving costs and times but it may also bring some limitations such as security and lack of trust. E-commerce still has a bright future and has the ability to change.

The summary of evolution e-commerce:

1984
Electronic Data Interchange (EDI) was standardized through ASC X12 and it is guaranteed that companies would be able to complete transactions with one another reliability.

1990
The first web browser, World Wide Web (WWW) was written by Tim Berners-Lee by using a NeXT computer.

1992
An online retail product was offers by CompuServe to its customers. This gives people the first opportunity to buy things using their computer.

1994
Netscape arrived and providing users a simple browser to surf the Internet and a safe online transaction technology called Secure Sockets Layer.

1995
Amazon.com and eBay.com which are the two biggest names in e-commerce are being launched.


1998
The Digital Subscriber line (DSL) provides faster and always-on Internet service to subscriber across California. This prompts people to spend more money and time.
1999
According to Business.com, retail spending over the Internet reaches $20 billion.
2000
The dot-com bust.
2003
Amazon had its first year with a full year of profit.




An example of an E-Commerce failure and its causes

The example of an E-Commerce failure that we choose is the DrKoop.com.


DrKoop.com was launched in July 1998 by Donald W. Hackett and John F. Zaccaro with $6 million from Superior Consultant Company Inc., a healthcare IT firm in Bloomfield, Michigan. Drkoop.com was a leading global healthcare Network providing measurable value to individuals worldwide. Its mission was to empower consumers with the information and resources they need to become active participants in the management of their own health. He is unlike most dot-com celebrities of the era; Koop owned a famous face before co-founding an Internet company and, indeed, before the Web even existed. As President Ronald Reagan’s surgeon general from 1981 to 1989, Koop and his iconic beard led a well-known anti-smoking campaign.

During the 1998 which in the operating revenues, It notched just $43,000, but that didn’t keep the company from going public in June 1999 and achieving, briefly, a peak market with capitalization of $1 billion. Subsequently, DrKoop.com’s business plan rested on advertising, and in 1999 there weren’t enough healthcare advertisers to support it and the many other healthcare dot-coms trolling for ad buyers.

However, the DrKoop.com fail to achieve complete success and are not able to face the challenges in market via Internet. Due to their unimpressive and non-persuaded marketing capacity as well as other weaknesses, they became bankrupt and failed to achieve success. Later, DrKoop.com, the medical information Web site that was once valued at over $1 billion, was sold to a Florida company for $186,000 in cash. Moreover, their shares, sold to the public in June 1999, rose as high as $45.75 three years ago, before falling with the collapse of the Internet stock bubble. Andrew Zipern (NYT)

There are several points that DrKoop.com fail:

  • E-commerce has perceived by the management as important to achieve the goals of the company. However, the DrKoop.com stills an unrealized goal of the health-care industry.
  • The Company sank into a cash crisis for the trademark, website and others.
  • It is difficult to build the trust and brand value associated with his name to the consumer via internet. Moreover, it is related the health, so the consumer need more approval and confidence.
  • Drkoop.com also is the target of several class-action lawsuits.
  • The DrKoop.com project has to be building around an important competence of the company.

The DrKoop.com project also has to add value for the user. They need to identify the demands and need of the consumers as well as to understand the market and the needs of the consumers. In conclusion, the DrKoop.com needs to implementation of effective business strategies and a strategic management process for the betterment of the company desirable for achieving long lasting success of an e-commerce company.

Here is some source of E-Commerce Failure

An example of an E-Commerce success and its causes

E-commerce is the buying and selling of goods and services via computer networks, such as those used on Internet and World Wide Web. E-commerce may be conducted B2B (business to business) or B2C (business to consumer).

An example of an E-commerce success is eBay. San Jose, California is the headquarters for eBay and overall probably has something in the neighborhood of employees. The eBay is the world’s largest online trading community. They offering users is an opportunity to come together in one Internet site and be able to buy and trade a wide range of items, including fine collectibles. It allows people to pursue their interest and passions in the areas of their hobbies and collectibles.


The eBay successes because it allows people to often times connect with some very fond and special early childhood memories. It could be anything from collecting baseball cards to toy soldiers to Barbie dolls to doll houses, and so forth. It allows people to make that connection and relive a lot of those very vivid and very fond memories that they have from an earlier period of time. Another factor is that people really enjoy the experience of the shopping bazaar. The users can enjoy looking around for merchandise. The other component is that users really enjoy the competition of the bidding process. Everybody likes to get a bargain, and everybody, in some way, shape, or form, likes to haggle a little bit over the price. The eBay auction format allows users to do that. The other thing is that as it has grown, it has become a very practical place to buy and sell collectibles or commodities.

The causes for eBay success, it’s a fun place to work because the great majority of people who are selling on eBay are really warm, decent, trustworthy and honest people. It's great to see how they interact and show those same characteristics toward their fellow eBay users. The eBay have created in how to sell their items. The eBay might be the first example where a commerce site has actually been built around a community where people are exchanging information and exchanging goods, services and merchandise. So, many people have established additional brick-and-mortar businesses are slowly moving a lot of that business over to eBay. For example: eBay sets the rules for commerce and implement them in order for transactions to be fair, cheap and foreseeable. Majority of the consumers can buy and sell with reasonable confidence as well as they will also get what they were promised, even though eBay still have flaws that are fraud and irregularities. Nowadays on the eBay, they continue to make changes and unite the policies and technologies that make day-to-day activities even more faithful, honest, and efficient.