Showing posts with label week 4. Show all posts
Showing posts with label week 4. Show all posts

The Application of Third Party Certification in Malaysia


Third Party Certificate (TPC) is a very new term to everyone i guess. What is Third party Certificate actually? A TPC endorsement has been used as one of the technique to implant customer's trust when doing online transaction using the internet. The implementation of TPC is very significant because the customers has a tendency to trust brand names. Thus, to increase customer's trust and eliminating the doubt in customer's mind is by getting a SSL certificate.
SSL stands for Secure Socket Layer. It is a protocol created by Netscape to make sure that there is a secure and safe transactions between web servers and browsers. In addition, it enables information to transmit back and forth securely. Applications that use the SSL protocol certainly know how to send and receive encryption keys with other applications, as well as how to encrypt and decrypt data sent between the two.









The SSL certificate is a digital certificate. It is a small data file that digitally shows the organization's details such as the domain name or server name, the company name and its location as well as the company contacts detail. This certificate is issued from a trusted Certificate Authorization The protocol uses a third party, a Certificate Authority (CA), to identify one end or both end of the transactions. Globalsign is one of the most trusted certificate authorities.






In Malaysia, the most well-known certicate authority (CA) is MSC TRUSTGATE.COM SDN BHD. MSC TRUSTGATE has started since 1999 to meet the rapid growth of the open network communications and become the catalyst for the growth of e-commerce of both locally and across the ASEAN region. MSC TRUSTGATE provides 5 main services which are Mytrust, SSL certificate,Digital Encryption, managed PKI and SSL VPN.


Furthermore, there is another product introduced by MSC TRUSTGATE - MyKey. MyKey, is the MyKad PKI solution that works with our physically MyKad, which allows us to authenticate ourselves online and to sign documents or transactions digitally and is accepted by the Malaysian government. Any action that uses the MyKey is legally bind by the individual.





Verisign is another example that offers SSL certificate. SSL is a trusted provider of Internet infrastructure services for the networked world. It provides authentication and verification of businesses worldwide. Billions of times each day, VeriSign helps companies and consumers all over the world to engage in trusted communications and commerce. Below is a link to youtube where there is a video that demostrates how to put purchase a SSL certificate from Verisign.com



In conclusion, why there are millions and billions of online sellers that applied the 3rd party certificate is because they wanna enhance the confidence of their consumers and clients during the transactions. Having or not a SSL certificate makes a significant different for the consumers because with a SSL certificate, it means that the website is safe and secure. Consumers will be more willing to deal with websites that have such certificates. Hence, there are many websites out there that sells goods and services have this SSL certificate.

If you are planning to do e-Commerce, do remember to purchase one ;p


  • Digg
  • Del.icio.us
  • StumbleUpon
  • Reddit
  • Twitter
  • RSS

The Threat of Online Security: How Safe is Our Data?

We are living in a digital world. We use emails and messenger to keep in touch with our friends and families. We upload images to social sites such as Facebook and Friendster. We do Internet banking. We purchase online flight tickets. We even shop online. As we slowly shifting our daily interaction or activities from the physical world into the digital world, how sure are we that our data is securely transfer? Or are we risking our privacy for the sake of convenience?

Image adapted from Jackson Benefit Group LLC

Like the physical world, there are many bad people in the digital world as well. They are interested in causing trouble to us by hacking into our account and take advantage of our private information for other malicious intention. So, if we are equipped with a weak password, those nasty intruders would able to guess our password without using any sophisticated tracking tools. Even if we are armed with a military-grade password, those genius intruder able to affix a bug or tracking device under our keyboards or simply create a phishing site to lure us into their trap, thus revealing our precious password to them.

Even we are sending emails, the process of sending the mail to the recipient could be tapped and confidential data could be leaked at the hands of the hacker. When we signed into our messenger, various messengers-ads will pop-up sent by our friends who are actually a victim of the messenger-spam chain, which includes advertisements or phishing sites to lure curious users to click the links. When we clicked the link, we actually downloading the malicious software and with the help self-installation, the "spy bug" will be installed into our computer. The spy bug will trace our log in information and password, thus giving it the access to send various fake ads links to our friends in the contact list. Some sophisticated spy bugs are even able to access to your email system and send fake ads links to all the friends in your address book. With the recent feature of allowing users to send offline message, these spy bug took the advantage to nag users by sending offline ads links.

 
A Real Life Example of Messenger SPAM
Click Image to Enlarge

It is human nature to keep things in the cupboard or storage area for future use. It is the same in the digital world. We do backup of precious photos, documents and videos to the Internet, trusting our Internet will be the secure and perfect storage area. Unlike in the physical world where we could lock in with padlocks, padlocks in digital world could be easily hacked if we have a weak password. Once our information are uploaded to the Internet, we are actually making them more vulnerable as the Internet makes our data easily accessable to anyone. Even we do trust our government in safeguarding our personal information, cases such as the biggest identity theft occurred in London where the tax authority had lost the data of 25 million people makes us doubtful on how far we can trust the level of security of the Internet in protecting our data.

Furthermore, with the increasing popularity of doing online transaction, more and more users prefer to shop or perform online banking through the Internet. However, with the high intelligence of the hackers, they are capable to duplicate the same website you used to shop, which you could easily submitting confidential data to these hackers. Hackers usually take opportunity when there is a seasonal hikes in the usage of online transaction, for example Transformer 2 release. A hacker could easily duplicate a cinema website and publish them at the convenience of the customers. Its like setting up a trap, waiting for desperate customers to fall into the trap.



GSC Temporary Site (on the first week of Transformer 2 launch): Potential Target for Phishing Site
Click Image to Enlarge

With so much vulnerabilities in the Internet, are we going to un-plug our Internet lines and remain shut forever in the offline world? Of course not. We have to take security measures to ensure our vulnerable data are safe from any potential hackers. To protect ourselves and our data, please read the post on Ways To Safeguard Our Personal Data by Dillen, or find out more about Phishing Sites by Kaw and the advantages of 3rd Party Security Certificates by Ally. With these security measurement taken, we could at least reduce the probability of our precious information being leaked out to the public.


Related Links:


  1. Data Vulnerability is a Systemic Problem
  2. How Safe is Our Personal Data?


  • Digg
  • Del.icio.us
  • StumbleUpon
  • Reddit
  • Twitter
  • RSS

Ways To Safeguard Our Personal And Financial Data


When making any transaction online such as online banking, online transaction or logging in to our own email account would enable any hacker to gain any information they need from passwords to credit card numbers. Therefore, we need to keep our data from as safe as possible and don’t even disclose it to your own friends.To safeguard our personal and financial data, we can do it in a number of ways.




Keep operating systems and browser updated

Keeping both of this updated will ensure any security flaws to be patch up and people will not be able take advantage by manipulating it to get our data.

Choose a strong password

Users should choose their desired password or PIN that are hard to be guessed by any person.Password or PIN are recommended to be at least 6 words long consisting of alphabet,numbers, lowercase and uppercase. Complex password is always the best choice as hacker will have a hard time cracking it.

Have an anti-virus and anti-spyware

By having anti-virus and anti-spyware would help to prevent any malicious program from embedding themselves in to your computer system. Literally by having both would not be enough if the user does not update and scan their computer on a regular basis. Having 1 type of anti-virus and anti-spyware is not enough as they do not guarantee a well protected computer. It is best to have additional anti-virus or anti-spyware for added security.

Avoid accessing in public area

Users should not access their personal or financial data using free wireless access that is available to them in the public. This is because data that is send through wireless technology can be easily traced and read unless the data is encrypted. Other than that, users should not access any sensitive data using public computer like in the cyber-cafe. This is because, there might be malicious program planted into the computer to capture data entered by unsuspected users.

Have a firewall

Having a firewall would actually slow that internet connection as they will go through a layer of protection that will scan and read any data pass through it. Firewall is recommended as they are able to block any unwanted communication from being establish to the web unless it is being expressly allowed by the users.

Secure Website
Users need to be aware of the pages they are visiting or web site where they are doing thier online transaction. Users should look for web pages that are secure which is usually have a "lock sign". Web pages which contain 3rd party certificate such as Verisign, Trustgate and others can help to minimize data from being stolen as they shows that a particular site have neccesary security features such as SSL (security socket layer) which provides security and data integrity over the internet.

Related Links:

  1. Yahoo.com
  2. Fool.com


  • Digg
  • Del.icio.us
  • StumbleUpon
  • Reddit
  • Twitter
  • RSS

Phishing: Examples and Its Prevention Methods.

What is phishing?? Phishing is a method and attempt to fraudulently and criminally obtain private and highly confidential information such as password, username, credit card numbers, bank account numbers and other private information. This is to invade people privacy. Phishing is done by stealing your identity where will be often asked to reveal private information such as password or other financial information. Phishing is carried out by email, yahoo, e-bay, Citibank, PayPal and so on.

Examples of Phishing:
From email

From credit card information

There are a few preventive methods that can be taken to avoid phishing. First is to keep your email and instant messages addresses private. This is because to prevent an individual to be tempted to respond to phishing tricks. Not to mention, it is also prevent these scams to land in your email and instant messages in the first place. Users are advised to use a separate email addresses when using any online financial transaction and so on.

Next is to report any phishing scam. If you suspect that messages contain phishing scam, immediately call the customer service whether you have received an actual message or not. Today, banks credit card lender and other financial institutes has their own website where suspicious emails and instant messages can be reported. Usually, in order to track down the perpetrator, they will require the users to fill up a form.

Finally, never reply to a email messages or instant messages that requires you to give out personal information. In addition, use a strong and do not use weak password for each of the accounts. Better still change them frequently to avoid any stealing of private information. Do always protect your personal computer by updating the latest anti virus and also use just one credit card for online purchases for convenient purposes. It is advisable to do business only to the companies or organization that you know well and trust.


  • Digg
  • Del.icio.us
  • StumbleUpon
  • Reddit
  • Twitter
  • RSS