CLICK HERE FOR THOUSANDS OF FREE BLOGGER TEMPLATES »
Showing posts with label week 4. Show all posts
Showing posts with label week 4. Show all posts

Tuesday, 24 June 2008

pic source : http://bux.to/?r=hackerz0308

Article from Ecommerze.blogspot.com


Impact - to fight cyber terrorism

Malaysian Government has approved RM43 million to set up an international centre which offer the world the best brains and facilities to help fight cyber security threats.

The center is called International Multinational Partnership Against Cyber Terrorism(IMPACT). It will be based in Cyberjaya with leading names in the IT industry serving on its advisory board.


This will be the world's first international public-private sector collaborative institution against cyber terrorism. This idea was brought out last year by our Malaysian Prime Minister at the World Congress on Information Technology in Austin, US.

Well known names like Symantec Corporation, TrendMicro, F-Secure and Kaperskylab have agreed to be the key partners and serving the advisory board.

IMPACT will be run and coordinated by two local IT companies namely Ascendsys Sdn Bhd, a security services company and GITN Sdn Bhd, a government IT network company.


source from http://ecommerze.blogspot.com/search/label/Internet%20Security


Blogger's comment :

The purpose of fighting cyber security threats is good and encouraging. Security threats have been an issue when dealing with any internet activities and also the nightmare to all internet users. Thus, implementation of this project is most welcomed. However, the real questions are:

1.
Does our government has the capability to respond as quickly and efficiently as possible?
2. Does our government has the necessary skills and knowledge to fend cyber-attacks?

These are crucial as we are dealing with high technology and it is ever changing and complicated. Frequent update and maintenance is vital to ensure the functionality of systems. Therefore, the government has to pump a sum of money into the maintenance works every year.

Take a look at government related websites, what do you think about those websites' maintenance? Are they up-to-date? Do they provide adequate information? Are they user-friendly? If the answers are majority yes, it indicates that the government is ready to implement such a project.

This project involves a huge amount of funds and thus a good and detailed plan is needed.to ensure the objectives achieved. Yet, I still have some questions. Can this project be carried out as planned? how to measure its effectiveness? Who, as a third party, will superintend the progress of project?

Looking at the past mega projects that launched by the government, which one has achieved its objectives successfully and efficiently? Proton? MSC? Singapore Bridge? Penang Bridge? Southern Johor Economic Region?

So, will this project be a success finally? We will wait and see.

Sunday, 22 June 2008

The threat of online security: How safe is our data?

In future Malaysia, e-commerce might be an usual transaction and most people trade online. However, it is hard to realize if the online security is not stringent enough. It is because one of the factors that influence consumer behaviour is perceived security and privacy. That is why until today e-commerce is not so popular in Malaysia even though it brings many advantages to the users.

I always read the news of whose credit card details were being leaked or stolen and suffered losses and inconvenience. When I purchased airline ticket through internet, somehow I have faith in the website's security level (maybe it is because the airline company is operating through internet and no security problem since incorporated). And, it proves that I was right because til today I have no subsequent problem.

Despite the websites have taken security procedures, there is certain level of risk we expose to. So, how can we protect ourselves when we engage in e-commerce activities? Be alert, resist temptation, don't simply believe in those generous offers, install antivirus,antispyware softwares...are not enough. We need to always update ourselves, knowing what is hot..(about what threats users are facing currently)

http://www.iss.net/threats/ThreatList.php
This website provides the latest information on Internet threats and vulnerabilities through notifications, such as X-Force Protection Advisories and Alerts. These notifications provide customers with information about how IBM ISS products and services can protect against the threat.

The Symantec Internet Security Threat Report offers analysis and discussion of threat activity over a six-month period. It covers Internet attacks, vulnerabilities, malicious code, phishing, spam and security risks as well as future trends.



Safer online shopping

source from http://youtube.com/watch?v=tXV8kMDsAuI

Saturday, 21 June 2008

Phishing




In computer, phishing is an attempt to criminally and fraudulently acquire sensitive information, such as usernames, passwords and credit card details, by masquerading as a trustworthy entity in an electronic communication.



Phishing technique was described in detail as early as 1987, in a paper and presentation delivered to the international HP Users Group, Interex. The first recorded mention of the term “phishing” is on the alt. online-service.



Phishing is typically carried out by e-mail or instant messaging, and often directs users to enter details at a website, although phone contact has also been used. Phishing ia an example of social engineering techniques used to fool users. Attempts to deal with growing number of reports phishing incidents include legislation, user training, public awareness, and technical measures.



An example of a phishing e-mail targeted at PayPal users. In an example PayPal phish (right), spelling mistake in e-mail and the presence of an IP address in the link (visible in the tooltip under the yellow box) are both clues that this is a phishing attempt. Another giveaway is the lack of a personal greeting, although the presence of personal details would not be a guarantee of legitimacy. Other signs that the message is a fraud are misspellings of simple words and the threat of consequences such as account suspension if the recipient fails to comply with the message’s requests.



Social responses – one strategy for combating phishing is to train people to recognize phishing attempts, and to deal with them. Education can be promising; especially where training provides directs feedback. One newer phishing tactic, which uses phishing e-mails targeted at a specific company, known as spear phishing, has been harnessed to train individuals at various locations.


Technical responses – anti-phishing measures have been implemented as features embedded in browsers, as extensions or toolbars for browsers, and as part of website login procedures. There are some of the main approaches to the problems, such as helping to identify legitimate sites, browsers alerting users to fraudulent websites, augmenting password logins and eliminating phishing mail.



Monitoring and takedown – several companies offer banks and other organizations likely to suffer from phishing scams round-the-clock services to monitor, analyze an assist in shutting down phishing websites.

The Application of 3rd party certification programme in Malaysia

Users won't transact business at a website unless they are certain it is secure. They need to ensure that your business is real and that their communications with you are private. VeriSign's solution is to issue SSL Certificate. SSL Certificate, also known as digital certificates, which is issued by a trusted third party called Certification Authority (CA),becomes the "passport" or the digital document that verify the security and authenticity of the interaction.

The SSL certificate is installed on a web server to identify the business using it to encrypt sensitive data such as credit card information. SSL Certificates give a website the ability to communicate securely with its web customers. Without a certificate, any information sent from a user’s computer to a website can be intercepted and viewed by hackers.

How SSL Certificate interaction with the Browser and the Server?

1. Browser checks the certificate to make sure that the site you are connecting to is the real site.
2. Determine encryption types that the browser and web site server can both use to understand each other.
3. Browser and Server send each other unique codes to use when scrambling or encrypting the information that will be sent.
4. The browser and server start talking using the encryption, the web browser shows the encrypting icon, and web pages are processed secured.


SSL certificates provide strong data encryption as well as reliable authentication of the site and the company with which a client is communicating. VeriSign looks to continued participation from its customers, technology partners to guide future development of products and services that allow internet user to use the internet as a secure medium for high-value online business, communications confidently.

Friday, 20 June 2008



How to safeguard our personal and financial data?






The e-commerce and e-business scene in Malaysia and around the Asian region is beginning to blossom. E-commerce technology coming to the market and the growing number of Internet users buying through the net stimulate the opportunity to expand the marketplace by deploying a cost effective and efficient solution. But one of the impediments of e-commerce success is the threat of online security. The best practices to help to safeguard your personal and financial data are:


Never reply to e-mail messages that request your personal information
Be very suspicious of any e-mail message from a business or person that asks for your personal information — or one that sends you personal information and asks you to update or confirm it. Similarly, never volunteer any personal information to someone who places an unsolicited call to you.



Password
If your account allows them, strong passwords combine uppercase and lowercase letters, numbers, and symbols, which make them difficult for other people to guess. Don't use real words. Use a different password for each of your accounts and change them frequently. It's hard to remember all those passwords.



Make sure the Web site uses encryption
The Web address should be preceded by https:// instead of the usual http:// in the browser's Address bar. Also, double-click the lock icon on your browser's status bar to display the digital certificate for the site. The name that follows Issued to in the certificate should match the site that you think you're on. If you suspect that a Web site is not what it should be, leave the site immediately. Don't follow any of the instructions it presents.



Can the Spam

Be very leery of "spam" (or junk email) that works its way into your email inbox. Not only are these messages often from phishers, but they can also contain Trojan horses (viruses) that can get into your computer and send your information back to their unsavory creators. Install spam-filtering software to keep your data safe.


Set Banking Alerts

Many financial institutions are beginning to offer email and SMS alerts when your accounts reach certain conditions (being near overdraft, or having transactions over $1,000, for example). Setting alerts for your accounts can ensure that you find out about unauthorized access as soon as possible.