Showing posts with label week 4. Show all posts
Showing posts with label week 4. Show all posts

Thursday, June 25, 2009

T.R.U.S.T (Third Party Certification)

WHAT'S THIRD PARTY CERTIFICATION?


















Third party certification is an assessment implemented to make sure there is compliance with industry standard. This method of securing transactions on the internet is well-embraced because it uses independent party.This technique is done by a third party organization that is qualified and licensed to issue certification. Certification will be licensed when the assessment is completed successfully.

WHAT'S UP?

Now we all know, of course, that "trust" is very very important when it comes to buying and selling online. Most people refuse to transact on the internet is because they lack of this element. Users are afraid that the sellers are either just pure scam bag, sending wrong items or poor quality items. On the other hand, sellers will also worry if the buyer is not genuine. I personally confess that I do not really trust buying things online because I simply do not have confidence in abstract shopping. Thus, what is stopping e-commerce is the "lack of trust" issue.

In the light of all these, MSC TrustGate and VeriSign have given solution to this matter, which is by the "third party certification". MSC Trustgate.com Sdn Bhd is a licensed Certification Authority (CA) operating within the Multimedia Super Corridor. MSC Trustgate was incorporated in 1999 to meet the growing need for secure open network communications and become the catalyst for the growth of e-commerce, both locally and across the ASEAN region.

TrustGate is licensed under the Digital Signature Act 1997 (DSA), a Malaysia law that sets a global precedent for the mandate of a CA. As a CA, Trustgate’s core business is to provide digital certification services, including digital certificates, cryptographic products, and software development.

TrustGate is also committed to provide the finest Public Key Infrastructure (PKI) to assist all types of companies and institutions conducting their business over the Internet.

Moving on to VeriSign Inc, it is the trusted provider of Internet infrastructure services for the networked world. Billions of times each day, our SSL, identity and authentication, and domain name services allow companies and consumers all over the world to engage in trusted communications and commerce.


















HOW DO THESE TWO SYSTEMS WORK?
1. Cryptography, the science of coding messages so that only a specific audience understands them, is an ancient craft that has become a highly specialized science in the digital age. Certificate authorities, like a latter-day notary public, provide encryption services for "netizens" of the world wide web that insure security for anything from credit card purchases to national defense intelligence.

2. Verisign/TrustGate, the certificate authority (CA) organizations, assigns a digital signature to a customer that contains two encrypted codes called keys--a private key that certifies the customer and a public key, which certifies the customer to anyone using the customer's web site. These codes form what is called a "secure socket layer", or SSL (a digital system developed by Netscape) that insures the website's authenticity.

3. Verisign/TrustGate verifies web sites using a process that examines traditional documents like articles of incorporation and business licenses as well as digital verification of each site operated by the organization. It is this certification process that is represented by the Verisign/TrustGate trademark on participating web sites. The trademark is generally found in an upper or lower corner of a page and any order forms where personal information is requested should display one. Most Windows systems also display a warning screen when the computer switches to secure mode.

4. Each web site is issued a public key and a private key. The public key allows consumers or users to encrypt their transactions using SSL technology. The private key allows authorized users of the web site to receive information sent using the public key. This double-handshake system assures consumers that their transaction is secure and that only authorized representatives of the recipient's company have access to the information (like credit card numbers or bank information) they've sent.

5. Public and private key encryption has been used by merchants for years, but many banks are beginning to add another layer of security for consumers by providing systems that allow the consumer to verify with his own private key. Although this adds a second step to the log-in process for banking and other financial activities, it is the next step in secure encryption and will become more prevalent as CA's develop new ways to protect against cyber-theft and terrorism.

6. Verisign/TrustGate session services are available in various bit (number or pieces of data, or complexity of codes) sizes, beginning with 128 or 40 bits. Public/private keys within certificates are issued in 512 or 1024 bit packages. Since Verisign/TrustGate IDs work on almost all browsers, these companies have become pre-eminent, controlling a majority of certification of sites.

IS THE IMPLEMENTATION OF THIRD PARTY CERTIFICATION IMPROVING CUSTOMER TRUST?

1.Easy-to-use and manage with Web-based user and administrator services.
Customer are able to register or apply for extra certification through via web, thus, it will help customers to have faith on the third party programme because so simple to use and it doesn’t require complicated procedures.














2.Efficient of management of digital certificates.
Customer authorization for digital certificate and certificate issuance are done via Web-based service. Both customer and administrator services are browser-based and accessed through the Web. Therefore, it will tremendously strenghthen customer trust because they can access the digital certification and inquire about the certificate online.

3. Availability of solutions
Customer will have a better solution provided by the administrator if there are any threats that tampers the company system. The user can contact the administrator to provide a solution to the customer to solve the problem. All in all, it will increase customer trust because of the efficient and effective management of the programme.

4.Complete control over digital certificate issuance, usage, certificate content.
By having this application users would have ultimate control over the service level and certificate. Unlike other public CA deployment model which customer only can rely on the public CA.

PROBLEMS WITH VERISIGN'S NEW FLASH-BASED "TRUST MARK" SEAL.
The newly designed VeriSign Trust Mark is positioned as a way for VeriSign's customers to better communicate the authenticity of their site to potential consumers online. Unfortunately, they implemented it very poorly. One of the Flash designer and developer, analyzed their implementation and found numerous problems, including several ways in which it can be trivially spoofed. His analysis, with a live demonstration, appears at http://www.infinitumdesign.com/verisign.html

Well, in my opinion, third party certification definitely helped in the trust issue by minimizing risk of information being leaked or exposed. However, nothing is a guarantee, so as users of internet, we should be more aware of the current issues on information privacy breaches and equip ourselves with necessary knowledge to avoid damages transacting online.

Wednesday, June 24, 2009

How to safeguard our personal and financial data?

1. Install a firewall to act as a gatekeeper which guards your network access.
This software checks whether data attempting to enter or leave your network should be allowed, according to rules that you define. It helps to prevent hackers from entering to your network to destroy, change or steal your data. DSL or cable modem provides an added layer of protection to your computer security as it comes with another built-in firewall while older computers or internet users who use dial-up connection are required to install a firewall separately.













2. Be vigilant while using the internet: look out for phishing scammers and viruses
contained in attachments.
Never open an attachment or click on a link embedded in an email from an unknown party. Even if the sender is a known party asking for personal details, one should independently verify the validity of the requests as well as the legitimacy of the organization. Phishers can bring you to a site which looks and feels like the authentic organization which you previously had dealings with. Also, look for small lock icon on the lower right corner of the browser window. Besides, attachments from mysterious sender can contain viruses which can corrupt your files and data.








3. Using encryption as a means to render data unreadable to unauthorized users.
Encryption is often used to achieve data security and privacy. It uses an algorithm to change the contents of computer messages or files into codes which are in an unreadable from, so as to prevent unauthorized eavesdropping along the transmission line. Only the authorized users have the “key” to convert the encrypted information or ciphertext back to a readable form.










4. Inquire web owners what precautions they have against malicious attacks
Database should be designed in a secured way, in which the database management system should not allow user to directly change the data, giving opportunities to hackers to abuse Structured Query Language (SQL) and reach parts of the system they should not be able to access. Although we are unlikely to be involved in writing a web application, we can, however, ask the web owners what precautions they have against SQL injections and other potential vulnerabilities before deciding to input our personal and financial data into its database system.

5. Back up your personal and financial information
This is certainly a sensible way to mitigate problems arising from data loss or files corrupted due to virus attack. Offsite copies of your data can be accomplished in two ways: 1) place hard copies of your personal data at a secured place; or 2) use an online service and synchronize your files with the off-site server.

6. Keeping operating systems and browser updated
Keeping both of this updated will ensure the computer to operate more efficiently and to include more security protection against infringement. Security flaws in the not-so-updated versions could be patched up in the up-to-date versions and this helps to reduce the possibility of Intruders to invade into the system and manipulating the data by taking advantage of the vulnerabilities observed.

7. Setting a strong password and be alert when you’re typing your password or pin number
A combination of uppercase and lowercase letters, numbers, and symbols will offer you a more secured password. Do not use personal information like your birthday, child’s name as your password as these can be easily guessed by others. Also, do not share your password or write it down, giving the others the opportunity to gain access to your personal and financial information. Moreover, shield your password with your hand when you’re typing it particularly in public area.











8. Install and update antispyware and antivirus programs
Virus will slow down the computer’s operation and cause data loss. Hence, do scan your computers regularly with these programs and keep them updated from time to time. This will inevitably prevent viruses, Trojan horse, spywares from attacking our computers.


To learn more, please refer to:
- Safeguard your financial life
- The best ways to safeguard personal data on social networks

Tuesday, June 23, 2009

Phishing: Examples and its Prevention methods

  • Phishing is an attempt of online identity theft in which confidential and sensitive information of an individual is obtained by disguising as a trustworthy entity in an electronic communication. Usually, a phishing scam can be seen in e-mail messages, social networking website, forged website which accepts donation for charity and instant messaging program. It often places links and directs users to enter details such as passwords, usernames, and credit card details under the pretense of the official or legitimate website.

  • Phishing scams
    Example 1: Below is a phishing e-mail which disguises as Internal Revenue Service of the United States

Abundance of e-mails is sent to potential victims advising them that they are under investigation by the IRS or that they have a refund pending from the IRS. The e-mail then asks the intended victim to “click here” which is a link contained within the e-mail to access the IRS website and prompts the victim for personal information, credit card numbers and credit card pin numbers.

Tips to avoid being a victim
• Tax payers should be aware that government entity such as IRS does not initiate tax payer communications through e-mail. IRB never sends out unsolicited e-mails to request personal information, credit card information and pin numbers.
• Do not reply, open any attachments or click on any links if you receive an e-mail claiming to be from IRS.
• Contact IRS by phone to inquire about your account if you believe it might be legitimate. However, most likely it isn’t.

Example 2: Bank phishing emails are very common too
Tips to avoid being a victim
• Most phishing e-mails will be addressed to either “Dear Valued Customer” or “Dear Sir/Madam”, while any legitimate emails from your bank or Credit Card Company will be addressed to you by name. Thus, be suspicious if generic greeting is used.
• Beware of forged links. HTML-formatted messages can contain links or forms that you can fill out just as you’d fill out a form on a Web site. Even if a link has a domain name which seems correct and authentic, it may not link to the real organization. Do not click on the link provided in the email. Also, it is preferable to call and enquire the bank that you usually deal with.

Notice in the following example that resting the cursor on the link, reveal the real Web address. If the string of numbers looks nothing like the actual company’s Web address, don’t click on it.

• “https” are safer websites than “http”. The “s” refers to as “secure”. Do not proceed if it is not an “https” website.
• If ever you’re required to open up a link, do not click on a link provided in the e-mail, rather, the best option is to open up a new browser window and type in the address which you know to be the authentic one. Or else, you could call the bank or company directly if you have dealings with them and have spoken to them by telephone before.
• The creation of sense of urgency by phishers is to entice people to react immediately without thinking twice about what they are doing. Internet users should always have a clear mind and not acting impulsively which will eventually lead them to be one of the victims.
• Generally, no legitimate business will request its client to send their passwords, login names, pin numbers or any other kind of personal information through an e-mail. If an e-mail requires you to submit personal data, it is probably a phishing attempt.

Example 3: Phishing case with Java Script on eBay.com
Perhaps the most sophisticated phishing scam is with java script. Scammers are given the opportunity to set up traps right on eBay.com as eBay allows java script to be manipulated. The internet criminal uses a forged feedback in order to make buyers believe he has a reputation at eBay. Check out the following:

Fake feedback
A feedback score of 120, Paypal buyer protection button and power seller.















Real FeedBack















To learn more about java script scam, please refer to :-
Acquiring personal information with java script

Other prevention methods of phishing scams:
Upgrading your browser to Internet Explorer 7 with built-in Phishing Filter which is designed to warn or block you from potentially harmful Web sites.
1. An excellent password manager helps to secure your logins, hide your keystrokes and encrypt your passwords. It is a guard against identity theft. It should not release your personal data if the site is not legitimate and has been spoofed.
2. Phoolproof Phishing Prevention. Please refer to:
Phoolproof Phishing Prevention

Take a look at these interesting articles about Malaysia’s online security issues:
• Cyber security in Malaysia Is rated above average
• Phish, your money’s gone!

The threat of online security: How safe is our data?

With the rapid advancement of technology, computerized systems have become a more preferred method among businesses and individuals than manual systems to store a vast amount of data and information. Consequently, the online security which protects data from loss, damage, abuse and misuse has become a major issue of concern for internet users.

Ironically, as the society becomes more and more technologically savvy, the risks of infringement of confidentiality and security of data increase as well. With internet being a medium which connects people from every nook and cranny of the world, it poses a great threat that jeopardizes the online security of data.

Cyber attacks fall under several categories: (1) Accidental Actions; (2) Malicious Attacks; (3) Natural disasters.

(1) Accidental Actions
Accidental actions includes matters such as setting poor passwords, accidental or incorrect business transactions, accidental disclosure of confidential information, outdated software which is easily trespassed by intruders as well as theft or misplace of notebooks which give rise to intruders to access to company’s data.

The root of causing these unintentional acts is attributed to the deficiency of basic knowledge about online security concepts which then result in using security products which are not configured properly. An incorrectly configured web server can allow even an unsophisticated hacker to access files and directories on the web server that should not be accessible. Ultimately, it leads to leakage of important information to outsiders due to insecure information transfers.

(2) Malicious Attacks
These are attacks which are aimed to do harm by breaking through the security defense created by the organization or individuals. The most common threats which internet users face nowadays are cybercrime, hacking, phishing and network attacks.

(a)Cybercrime & Hacking
Cybercrime is the use of online computers as an instrument to conduct illegal acts. Since the internet is inherently open, computer and network experts such as crackers, hackers and corporate spies are “hired” to gain access to competitors’ server to destroy data, change or steal important information without proper authorization given. It involves the violation of privacy of others and it typically attacks computer-based property such as files or web pages.

Hackers can easily learn about the targeted company’s web-based applications and discover its vulnerabilities in order to disguise as genuine users who are able to connect to the company’s web server and do whatever a user could do. For instance, hackers can attack by using SQL injection by circumventing the username and password required to gain access to the database and easily alter the stored data such as ledgers.



(b)Phishing
Internet scam that is designed to trick the recipient into revealing credit card details, usernames, passwords, and other personal information to individuals who intend to use them for fraudulent purposes is known as phishing. The communications are sent in the manner that it looks as if they come from reputable and trustworthy companies. Very often, a phishing attempt requests the recipient to verify their bank account by asking them to click on a link provided in the email and giving his/her personal information. The consequences of giving such confidential information to an unknown person could be very severe.

(c) Network Attacks
Several forms of malicious-logic program are virus, Trojan Horse, computer worm, Denial of Service attacks and etc. Virus, being the most common type of malicious code, its attack is pervasive, in which it can damage the operating system, spread throughout the computer and infecting other computer files, rendering files being corrupted or causing data loss or damaged.

A Trojan Horse is a program that secretly hides within or looks like a legitimate program giving people the impression that it is harmless. However, one may realize that it actually will do harm to one’s computer and data files when it is triggered with certain conditions satisfied.

Distributed Denial of Service attacks (DDOS) attack a web server by overwhelming server with overflowing messages which appear to be normal. The DDOS attacker will instruct its key players to simultaneously send data packets against the given IP addresses using false source addresses. Since the attack contains too much information to be processed, the target server has no choice but to disconnect from the internet or by denying service indiscriminately to all clients sending incoming data. Hence, this shows a potential risk of data loss in transit as client may not know whether his/her data sent is received by the web server.


(3) Natural disasters
Natural disasters also pose a threat to online security. Natural disasters such as fire, flood, earthquake which occurrence at the place where server and database hardware are located can cause data stored to be destroyed or lost. Hence, a comprehensive disaster recovery plan should be in place before any unpleasing event happens.

Related links:-
Computer Security Ethics and Privacy
Top Online Security Threats for 2009
Computer Security, Viruses and Threats