THOUSANDS OF FREE BLOGGER TEMPLATES

Monday, June 29, 2009

Electronic Currency


Electronic currency also called e-money, electronic cash, electronic money, digital money, digital cash or digital currency. Usually involve used of several systems, such as internet, computer network and digital store system. It is also refers to the money or scrip which is exchange by electronically.


By using the e-currency service on the internet like e- gold and paypal provide a convenient, secure, and cost effective for people. E-gold is a digital gold currency operated by Gold & Silver Reserve Inc. under e-gold Ltd., and is a system which allows the instant transfer of gold ownership between users. Besides that, E-gold is payment system that can let people to use gold as money.


On the other hand, PayPal is how business transaction parties send and receive money online. PayPal is substitute traditional paper methods such as checks and money orders. We can use it to make payments globally through the internet.



Pro of E-currency
The using of the E-currency services, people no longer use their credit card making online payment. Since there is the risk of expose of their credit card confidential information. While E-currency can help us avoid this kind of problems.

The E-currency system are using through the internet, provide convenience for all the users. Since the internet can accessed anywhere in the world. For example, when user wants to make payment into the bank, they do not have to actually go to the bank to make such payment. The online system also provides convenience to the user, as he or she does not have to queues, waiting for the payment.

Cons of E-currency
One of the major cons of E-currency system is fraud. If the private key is misplace by the consumer, and used by a perpetrator to withdraw funds. In this case, the bank wouldn’t even know, hence the consumer will be liable by self. Due to this reasons, of course, the risk is even greater in traditional forms of payment.

In fact, E-currency system depends a lot on the technology. We will worry that, if the power failure, unavailability of internet connection, undependable software and loss of records, especially when we rush to do the transaction. All this problems will add difficulties to users.

In conclusion, more and more advanced technologies provide a lot of convenient for us. However, we need to be carefulness when we using it, to avoid other people stolen our confidential information.

Related link:

http://www.e-gold.com/benefits.html

http://www.buzzle.com/articles/pros-and-cons-of-electronic-cash.html

http://www.latestbusinessupdates.com/3-top-advantages-and-disadvantages-of-the-electronic-currency-payment-system.html#more-218




Friday, June 26, 2009

The application of third party certification programme in Malaysia

Third party called certificates authorities. A certificates contains holder’s name, validity period, public key information and a signed hast of the certificate data.

Third party certification programme is an authority and authentication that ensures trust, privacy and safety between each individual, company and entities.


Defenses of third party certification programme

  • Confidentiality – it is refers to information held by an organization that it necessary to protect securely. For instance, bank must protect clients’ sensitive personal information. Clients want to be assured that information they provided for processing or storage is protected and only accessible to authorized users.
  • Authentication – it is requires evidence such as password or signature.
  • Availability – tools such as software and hardware help ensure availability.
VeriSign is the best known of the certificates authorities. VeriSign provides several of security and telecom services such as digital certificates and e-payments. VeriSign is the leading Secure Sockets Layer (SSL) which is certificate authority enable secure e-commerce, communications and interactions through web sites, intranets and extranets. SSL defined a protocal that utilizes standard certificates for authentication and data encryption to ensure privacy or confidentiality. Actually SSL is renamed as Transport Layer Security (TLS), however, many people never changed and still use it as SSL. For instance using SSL such as Maybank online credit card payments.


VeriSign Secured Seal is part of VeriSign®SSL Service. SSL assist deliver a secure and convenient way for everyone to interact over the internet. In addition, VeriSign Secured Seal is the most trusted security mark on the internet and gain confidence to complete everyone tasks or transactions.


Webtrust is a certification authorities that protected against unauthorized access. Since the information or transaction share with a website can be misused or stolen. The trust service security priciple addresses concerned by ensuring that business maintain secure sites for e-commerce such as e-payments.

Public key infrastructure (PKI) defined a scheme for securing e-payments using public key encryption and several technical components. It refer such as digital signature. Digital signature is a term used for marking or signing an electronic documents. It is based on public keys for authenticating the identiy of the sender of a message or document. There are exhibit shown that the process of digital signature.


In effect, third party certification programme is play a significance role for organization in Malaysia. They are provide trust, privacy and safety ensure that client’s personal information or transaction is protected and availabitlity over the period. Hence, the effectiveness of third party certification programme in enhancing security is sustaintable.

Reference:

http://www.verisign.com/

http://www.webtrust.org/index.cfm/ci_id/44946/la_id/1.htm

http://www.webtrust.org/index.cfm/ci_id/44946/la_id/1.htm




Thursday, June 25, 2009

Phishing : Examples and its prevention methods

Phishing is attack technique where the attackers send an email or instant messaging declares to be from an existing financial institute or e-commerce provider. The email often uses fear tactics in an effort to attract the intended victim into a fraudulent website. The fraudulent website will look similar with the true website.

It will require the victim to login to their account, in addition to enter sensitive financial information such as their bank PIN number, credit card details, Social Security number and more. Normally, the email request the user to update their credit card information or else their account will be terminated. By other way, it will offer a service to protect their credit card from possible fraud. After that, the information that receives will sent to the attackers who then use it to create credit card and bank fraud.

By the way, it also create fraud where the phishing email will send to the user and tell him that he was won in a competition of lottery. It will need the winner to provide certain personal information in order to get the reward.

The following are some example of phishing.

http://antivirus.about.com/od/emailscams/ss/phishing_2.htm

This is a phishing scam which sends to Washington Mutual Bank customer. It requires the customer to verify their personal data since the bank is updating their system.

http://netforbeginners.about.com/od/scamsandidentitytheft/ig/Phishing-Scams-and-Email-Cons/Internet-Scams--lottery-3.htm

This email trying to get the victim personal data where saying he had won the lottery and need the victim to provide personal information to make sure the reward will not be double claiming.

Figure 1(a) - Maybank 2U Portal

Figure 1 (b) Maybank 2U Login Page

Figure 2 (a)- Phishing Site

Figure 2(b)- Phising Site Login Page

http://www.ictsecurity.gov.my/readTxtFile.jsp?URLLINK=MaybankPhishing.pdf
The figure 1 is the real website of Maybank, while the figure 2 is the phishing website of Maybank. To differentiate these 2 website is to refer the address bar . (http:// is the correct URL prefix)

To prevent the phishing website and email. There are several prevention software or some tips when receiving the phishing website.

Phishing Detector v1.0 is a anti-phishing tool that detect phishings, email frauds and spoofed emails at the inbox with one click. It able to detect the phishing email that come from eBay, PayPal and others financial institute.







Tipping Point's Phishing Protection is using combination of vulnerability filters, signatures, and behaviour-based protection technique to detect and prevent phishing. TippingPoint anti-phishing filters block at every phase of phishing attack.






NETGATE Internet Security v2009 is a complete security protection software which can detect most of the serious Internet threat. It include spyware, viruses, torjans, phishing, spam and more. This protection will make the user more convenience since it consists all the features in one.



If receive an email or pop-up message that ask for personal or financial information, do not reply it and click on the link that provided. The legal financial institutes or website will not ask their customer to provide any confidential information via Internet. Normally, the Internet criminal will not type the receiver's name, this due to they will send the phishing email in bulk. Be careful when email with some attachment or downloading files, it might contain viruses or phishing.

It will easy to determine the phishing email and website. As a user, we need to always alert where there are suspicious of any email with urgent requests for personal financial data. They will make you to feel it is urgent and important. A phishing email is to trick you into providing the information. If you feel you might to reply on it, you better call for your financial institute to ensure the genuine of the website.

It also can prevent by using anti-virus and anti-phishing software. However, it will more effective with the software is update frequently. Beside that, we should not email our personal information to anyone or fill up form in email messaging. If have to do so, make sure the website is secure, look the security look and URL for a website that begins with "https", the "s" stand for secure. Furthermore, always review credit card and bank account statement to check any unauthorized charge. If anything that you do not recognize transaction, contact your bank immediately. Lastly, remember to report phishing email or phishing website to the respective organization.

In my opinion, we should always alert on the phishing website and email. We should not provide our personal information to any people via Internet. We must always aware the URL of the website, to ensure it is secure. If unfortunately that you have trick in phishing, you must report to http://www.antiphishing.org/ or visit to Government Security Web Portal(http://www.ictsecurity.gov.my/)




References:
http://www.cyberoam.com/phishing.html
http://en.wikipedia.org/wiki/Anti-phishing_software
http://www.antiphishing.org/consumer_recs.html
http://www.onguardonline.gov/topics/phishing.aspx
http://www.filebuzz.com/files/Phishing_Prevention/1.html

Wednesday, June 24, 2009

How to safeguard financial & personal data

Financial data and personal data are confidential data for every person. It consists a lot of private information that cannot be known by others. Nowadays, there is a lot of victim that fall under online fraud or identity theft. Hence the fraud or identity thefts cases are increasing such as passwords, bank account numbers or credit card numbers were stolen. Therefore, it is important that we use some necessary ways to safeguard the data which is needed for the personal data to be secured.

Firstly, you have to choose passwords that would be difficult for someone who knows you to guess. Many people like to use their birth date or phone number as their password, this is definitely wrong. It is because not only the hacker but your close friends also can be easily figure out the password and hack into your account. Besides that, make the passwords more complicated and different for every different website. So it is hard for a person to crack the password and the person is unable to steal all the financial or personal information.

Next, keep your financial and personal data off your computer. Try to avoid for keeping some bank account numbers or passwords in the computer. It is easy for a hacker or spyware program to hack into your computer and detect all the sensitive data. Hence we should buy an external hard disk or thumb drive to store all the confidential and sensitive data. It is simple and effective way to prevent data theft. Thus we only have to plug in the drive whenever we need to refer on the data.


Thirdly, install anti-virus or anti-spyware software into the computer. Not only that, you should also keep the software up to date so it is able to detect all the virus or spyware in the computer. Without an anti-virus software, any virus or worms can spoil all the information in the computer and steal it to earn money. As well as the data get stolen, the computer will also run slower if there is some virus or Trojan horse in the computer.

Last but not least, be more alert when take the computer for fixing. People simply trust technician and hence hand over the computer to them when something goes wrong. It is just a piece of cake where the technician can easily copy down all the personal data for themselves. So it is important that people should delete all their personal information before hand it to the technician. In another way, they can request the technician to come over to their house to fix the computer and you just watch as they do it.


Reference:

http://www.online-tech-tips.com/computer-tips/13-ways-to-protect-personal-data-from-online-fraud-and-identity-theft/zh/

The Threat of online Security: How safe is our data




Nowadays, computer users are facing the threats of cybercrime, phishing, internet and network attacks such as computer viruses, worms and Trojan horses and back doors. A threat to an information resource is any danger to which a system may be exposed.





Denial of service (DOS)
An attack on a web site in which an attacker uses specialized software to send a flood of data packets to the target computer with the aim of overloading its resources.


Back door
A back door is a set of instructions in a program that allow users to bypass security control when accessing a program, computer, or network. Once perpetrators gain access to unsecure computers, they often install a back door or modify an existing program to include a back door, enabling them to continue to access the computers remotely without the user’s knowledge.



Malicious Code: Viruses, Worms, Trojan horse
Virus is a piece of software code that inserts itself into a host, including the operating systems; running its host program activates the virus. A virus has two components. First, it has a propagation mechanism by which it spreads. Second, it has a payload that refers to what the virus done once it is executed.
Worm can spread itself without human intervention. Worms use networks to propagate and infect a computer or handheld device and can even spread via instant messages.
Trojan horse is a program that appears to have a useful function but that contains hidden functions that present a security risk.


On the other hand “Hacking” a computer which is another threat is the act of exploiting vulnerable operating system functions, applications, and peripherals to gain unsolicited access to a computer or network. It also describes someone who attempts to break into computer system. This kind of hacker has the sufficient technical knowledge to understand the weak points in the security system and act maliciously.


In conclusion, risk exposed by computer users is increasing with the increasing developed technology. Therefore, safeguards developed must be always up to date to enhance the defenses against online security threats.



My suggestion “How to Prevent Threat”
Computer system is very important for the organizations. When the organizations computer system attacked by the computer viruses, it may cause important data to be lost. Therefore, organizational should install update anti-virus software such as Kaspersky Antivirus, AVG Antivirus software, Norton Antivirus, Avast Antivirus and so on. Besides that, organizational must concurrent backup their data and files.