Showing posts with label week4. Show all posts
Showing posts with label week4. Show all posts

Sunday, June 28, 2009

How to safeguard our personal and financial data




How to safeguard our personal and financial data


Internet is a public network of nearly 50,000 networks connecting millions of computers throughout the world. Nowadays, most people rely on the internet to store, create and manage critical information. Information transmitted over the internet is more vulnerable and has a high degree of security risk. Since they are publicity, the internet users are facing many problems that their personal and financial data has been stolen. Hence, we should take some actions to increase the internet security and prevent data from being stolen.

There are some approaches on how to safeguard our data:

1. Set up username and password

Setting up the username and password is the most common ways that people use to ensure security from being stolen by third parties. However, the password used must be longer since it provides greater security than the shorter ones. Furthermore, avoid using passwords that are easy for someone to guess, such as date of birth or hand phone number and never write it down. Not only that, we could not disclose password that related our personal data and financial data to third party and change it frequently.

2. 2. Encrypt the data before send it out

Encryption is a process of converting readable data into unreadable characters to prevent unauthorized access. When the data is transmitted from one location to another, we should encrypt the information before sent it out since outsiders are unable to read the encrypted message. In order to protect data on the internet and networks, individual may use a variety of encryption techniques to keep security and privacy of data.

3. Installation of Firewall and Anti-Virus

The simplest way to protect personal and financial data is through use of firewall and anti-virus which enable the users to protect them from worms and Trojans. Nowadays, AVG and MC Afree and Symantec are popular software used by the computer users. Users can use firewalls to protect their computers and data from unauthorized intrusions. In addition, the firewalls can prevent the hackers from hacking our data. Moreover, we have to install the antivirus software to protect against some viruses that are very harmful. Generally, the antivirus software has the automatic update feature which provides the better protection from the new virus that popping up from the internet.

4. Biometric device

Biometric device is an access control to safeguard our personal and financial data. It grant access to programs, computers, or rooms using computer analysis of some biometric identifier such as fingerprint scanners, face recognition system, signature verification systems as well as iris recognition systems. Today, biometric devices are gaining popularity as a security precaution since they are a virtually foolproof method of identification and authentication.


Saturday, June 27, 2009

The application of Third party certification programme in Malaysia

Third-party certification is a scientific process by which a product, process or service is reviewed by a reputable and unbiased third party to verify that a set of criteria, claims or standards are being met.
Certification authority (CA) is an entity that issues digital certificates for use by other parties. It is an example of a trusted third party.



VeriSign, Inc. is one of the certification authorities. It is an American company based in Mountain View, California that operates a diverse array of network infrastructure, including two of the Internet's thirteen root name servers, the generic top-level domains for .com and .net. It is the leading Secure Sockets Layer (SSL) Certificate Authority which also enabling the security of e-commerce, communications, and interactions for Web sites, intranets, and extranets. It provides security solutions to protect an organization’s consumers, brand, Web site, and network. Besides, it also provides a variety of security and telecom services ranging from digital certificates, payments processing, and managed firewalls to mobile call roaming, toll-free call database queries and downloadable digital content for mobile devices. The company groups all of these functions under the banner of 'intelligent infrastructure' services.



MSC Trustgate.com Sdn Bhd is also a licensed Certification Authority (CA) operating within the Multimedia Super Corridor. MSC Trustgate was incorporated in 1999 to meet the growing need for secure open network communications and become the catalyst for the growth of e-commerce, both locally and across the ASEAN region. At present, MSC Trustgate has 12 million in paid up capital.
Trustgate is also licensed under the Digital Signature Act 1997 (DSA), a Malaysia law that sets a global precedent for the mandate of a CA. As a CA, Trustgate’s core business is to provide digital certification services, including digital certificates, cryptographic products, and software development.




Examples of Phishing and Its Prevention Methods


What is Phishing??

Phishing is intentional acquiring of personal and sensitive information from the victim by masquerading as a business or individual. A scammer tries tricking someone at the website to obtain private information such as username, passwords and credit card numbers. It is usually carried out by e-mail or instant messaging and directs user to enter their personal information at a fake website. Normally, it is largely used in paypal, and others similar payment processors for instant banks, credit cards and eBay.

You might see a phishing scam
  • In e-mail messages, even if they appear to be from someone you know.
  • On your social networking website.
  • On websites that spoof your familiar sites using slightly different web addresses, hoping you won’t notice it.
  • In your instant message program.
  • On your cell phone or other mobile device.

Examples of Phishing

Example 1: Phishing scam in e-mail message

The scam artists may place a link in them that appears to go to the legitimate website (1), but actually takes you to a phony scam site (2) or possibly a pop-up window that looks exactly like the official site.

Example 2: Obfuscated URL

This example uses a technique known as URL spoofing. The origin of this technique is that a malformed URL will not be displayed properly by certain web browsers, and this allows the hacker to trick you into thinking you are on a legitimate website.

In this example, the hacker sends an email containing a graphic asking you to click the link:

Despite appearance, the link tries to take you to:

http://olb.westpac.com.au[special unprintable characters]@68.112.112.35:8888/asp/index.htm


The nature of the web browser fault is that everything after the special unprintable characters will not be shown in the address bar, so all you see is http://olb.westpac.com.au, which makes you believe that you are on the real Westpac website.

For most recent information please visit to the Antiphishing Website:

http://www.antiphishing.org/

How to prevent Phishing??

Never give sensitive personal information in a message

Be very skeptical of any emails, instant message or pop-up window that asks for your personal information. If a bank or other company really needs to get some specific information from you, they'll most likely send it in writing or via a secure email.

Make sure the website is legitimate

Do not simply enter personal information unless you're sure it is to a website you are trusted and that the site takes appropriate steps to protect your data.

Be wary of clicking a link in a message or pop-up window

If you get an e-mail, instant message, or pop-up window that asks for personal information, do not click the link. Because it may take you to a phony site where any information you give may be sent to the phisher who built it. If you’re in doubt call the company to ensure that whether any messages are sent by them.

Improve your computer's security

Phishers hope you haven't been applying the latest security fixes, and may try to take advantage of these vulnerabilities. Some phishing e-mail may contain malicious or unwanted software that can track your activities or simply slow down your computer. Therefore, you should update your computer system regularly.

Friday, June 26, 2009

The Threat Of Online Security: How Safe Is Our Data?

No doubt that Internet is not only a public system in which every transaction can be tracked, logged, monitored and stored in many locations, it is also one of the resources for computer users to search their information. Due to this apparent convenience, it provides the opportunities for them to share the knowledge without filtering the content. Thereafter, everyone can indirectly learn skills that may jeopardize online security through Internet and this directly enhance the online security risk. Thus, it is essential for computer users to clearly understand those potential online security threats that may interrupt their data.

The potential online security threats that can be discovered are listed as follows:

Cybercrime is defined as online or internet-based illegal acts. This may occur when hackers, crackers and corporate spies access computers and networks illegally with the intent of destroying data, stealing proprietary data and so on.

Besides that, Phishing is a scam in which a perpetrator sends an official looking e-mail that attempts to gain your personal information and financial information. For instance, some phishing e-mail messages ask you to reply with your information, or a pop up window that looks like a website that collects the information. The damages caused by phishing can be serious. The following case depicts the online security threat that is caused by phishing.

In 21 June 2007, a spear phishing incident at the Office of the Secretary of Defense (OSD) stole sensitive U.S. defense information, leading to significant changes in identity and message-source verification at OSD. This incident has cost administrative disruptions and personal inconveniences, as well as huge financial loss in making system recovery.

On the other hand, Internet and network attack that jeopardize online security include virus, worm, and Trojan horse. Virus is a piece of code that is secretly introduced into a system in order to corrupt it or destroy data. Virus attack can damage the operating system, causing the loss of data and other possible losses. Furthermore, worm can be expressed as a program that copies itself repeatedly. The repeatedly copied files use up the available space and slow down a computer operating speed. In addition, Trojan horse refers to a program that hides within or looks like a legitimate program. Regardless they seem to be harmless, they may however be triggered if certain condition is certified.

Last but not least, back door is a set of instructions in a program that allows users to bypass security control when accessing a program, computer, or network. Once perpetrators gain access to unsecured computers, they often install a back door or modify an existing program to include a back door, enabling them to continue to access the computers remotely without the user’s knowledge.

As a conclusion, online security threats are very real, but if you know how you become vulnerable, you will be able to better protect yourself. You should be able to get online without constantly worrying, and you can! In other words, data safeguards developed must be always up to date in order to increase the defenses against online security threats. At the same time, computer users must be educated and equipped for the information of the crucial damages and losses that caused by imposing online security threats.

References:
http://www.govexec.com/story_page.cfmarticleid=39456
http://en.wikipedia.org/wiki/Timeline_of_computer_security_hacker_history