Saturday, June 27, 2009

The Application of 3rd Party Certification Programme In Malaysia

Third Party Certification (TPS) is an assessment carried out to ensure satisfaction and confidence of customers. The increasing phishing and spoofing attacks on the internet has boost the implementation of TPC programme to ensure the information traveled over the internet reaches to the recipient safely. The TPC programme requires the posting of a website privacy statement to inform a visitor about what peronal information a web site may collect from them and how it will be used and disclosed amont other features.

Security is the primary concern of entering into a new internet economy. The ever-changing paradigm of e-commerce requires a well-mandated security infrastructure.



MSC Trustgate.com Sdn Bhd is the most famous application of third party certification programme in Malaysia. It is a licensed Certificate Authority (CA) operating within the Multimedia Super Corridor. MSC Trustgate was incorperated in 1999 to meet the growing need for secure open network communications and become the catalyst for the growth of e-commerce, both locally and across the ASEAN region. The vision of Trustgate is to enable organizations to conduct their business securely over the Internet, as much as what they have been enjoying in the physical world due to the issue above.

Trustgate's core business is to provide digital certification services which including digital certificates,cryptograhic products, and software development. There are several products provided by Trustgate, such as SSL Certificate, PKI, Personal ID, MyTRUST, MyKad ID, SSL VPN, and etc.

MyKad PKI

Malaysia Government has put in place a smart National Identity Card (MyKad) for every citizen. My Kad with PKI capability allows its holder to conduct online transaction with governement agencies private sectors.

MyKey is the MyKad PKI solution that works with the physically MyKad which allowing to authenticate users online and to digitally sign documents or transactions and is accepted by the Malaysian Government.

MyTRUST
For Mobile Signature
Users can turn a SIM Card into Mobile Digital Identity for secure banking and other financial services with MyTRUST. Users are able to digitally sign any transaction with ease and convenient via their mobile phone.

For Government


For Banks & Enterprise
SSL Certificate
SSL is the short for Secure Sockets Layer. It is a protocol developed by Netscape for transmitting private documents via the Internet.
VeriSign is the leading SSL Certificate Authority that enabling secure e-commerce, communications, and interactions for web sites, intranets, and extranets. It choose the most trusted mark on the internet and enable the strongest SSL encryption available to every site visitor.


When we see the VeriSign logo on the website, we can click on the seal to find out more about the security of the site.

Public Key Infrastructure (PKI)
Trustgate provide PKI to assist all the companies in conducting their business over the internet.
Organizations are helped by PKI technologies to enhance the security of the data and manage identification credentials from the users and organizations. It helped to secure by based on the exchange of digital certificates between authenticated users and trusted resources.

Last but not least, TPC can enhance customer trust because of its efficient management of digital certificates. It also have a complete control over digital certificate issuance, usage, and certificate content. Besides, it is easy to use and manage with web-based user and administrative services. Scalability of TPC also provide customers a better solution if there are any treats happen toward the computer system.
Related links:
  1. http://www.verisign.com/
  2. http://www.trademal.com/global/index.php/id/17463/target/about/MSC_Trustgate_com_Sdn_Bhd/index.html
-Mun Yee-

Friday, June 26, 2009

Phishing: Examples and its prevention methods

This summary is not available. Please click here to view the post.

The threat of online security: How safe is our data?



Online security threats are one of the biggest challenges for most of the organizations today. Organizations continue to experience cyber attacks from inside and outside of the organization. In addition, the types of cyber attacks that organizations experience were varied. These made organizations started to worry that the user's break into the server purposely is to alter the pages and content at the site. Besides, they would also worried about the disruption of server by user, because by doing that would possibly made it unavailable to other.

Cyber attacks fall under several general categories:
(i) accidental actions
- A large number of computer security risks are contributed by accidental actions. Most of the users nowadays are lack of knowledge about online security concepts, these includes poor password choices, accidental disclosure, erroneous or even using a outdated software. For example, many people are using facebook, friendster, ebay and others. All of these are actually need user to enter their user name and password to log in. The problem is people are tend to use their IC number, birthday, or even an "easy memorize number" like "1234"as their password. This make it easy for people to figure out their password and break into their account. However, this form of cyber vulnerability is avoidable if education and prudence are being considered.

(ii) malicious attacks
- Attacks that specifically aim to do harm. It is at root of so-called "crackings" and "hackings"-notable examples of which include computer viruses, denial-of-service (Dos) attacks, and distributed denial-of-service (DDos) attacks.

* computer viruses
- a piece of software code that inserts itself into a host, including the opearating system, to propagate; it requires its host program be run to activate it. A virus will simply infect and spread over the operating system and consequently cause the server system broke down. As an example, the May 2000 "I LOVE YOU" virus. A small piece of code attached to electronic mail (E-mail),and double-clicking on the executable caused it to send an e-mail to everyone in an address book, subsequently damaging victim's machines. The virus caused over $100million in US damages and over $1million in worldwide losses.

* denial-of-service (Dos) attacks
- an attack on a web site in which attacker used specialized software to send a flood of data packets to the target computer with the aim of overloading its resources. It may cause a network to shut down, making it impossible for users to access the site.

* distributed denial-of-service (DDos) attacks
- a denial-of-service attack in which attacker gains illegal administrative access to computers on the Internet and uses them to send a flood of data packets to the target computer. Such attacks were witnessed in a number of large corporate computer shutdown in 2000.

(iii) online fraud
- A broad term covering Internet transactions that involve falsified information. There are 2 major form of online fraud: identity theft and data theft.

* identity theft
- the theft of personal identity on the internet is the newest form of fraud. A person may open a credit card account by using a false identity such as the victim's name, address, or bank account. Besides, since it's impossible to identify the identity of buyer through online, a person can also do online transaction using victim's identity if they can get the victim's personal information.
- Talking about identity theft, I have an experience before. My sister's boyfriend (A) ever used my account to chat in messenger with my friend and my friend didn't aware about it even until they finished the conversation. Sounds so funny! At the moment, I realize that there is "online security threat" in messenger too. "A" using my identity while my friend can't even recognise who is she dealing with. These shown that there is lack of proper security to detect people's identity and thus enable a person to do whatever he/she want using other people's identity.

* data theft
- the theft of information , unauthorized data, or manipulation of private data. Data theft is a problem primarily perpetrated by office workers with access to technology. Since employees often spend a considerable amount of time developing confidential and copyrighted information for the company they work for, they often feel they have some right to the information and are inclined to copy/delete it when they leave the company. Besides, they might also misuse it while they are still in employment.
- In April 2001,2 employees of Cisco System were obtained unauthorized access to Cisco stock and they broke into the computer system that handled stock distribution. They were able to transfer stock shares nearly $6.3million to their private portfolios.

As the conclusion, the financial losses from a cyber attack can be substantial. Except the financial losses, it also bring other effect to users. These shown that the online security still need to be improved. Security requirements such as authentication, authorization, and confidentiality also need to be considered.

Posted by: Shu Hui

Thursday, June 25, 2009

How to safeguard our personal and financial data

As Internet criminals grow smarter and sneakier, Internet is no longer a safe place. It is increasingly difficult to keep your financial and personal information safe because hackers have the ability to get that information. Have you done proper safeguards for data? If you don't take basic steps to protect your data, you may find yourself a victim of fraud or identity theft.

Here are a few tips on how to safeguard your personal information:

~ Password protection
While you choose passwords (you'll remember), please make sure that passwords is not be something that are easy for someone else to guess, such as the name of your child's name or your date of birth. A combination of uppercase and lowercase letters, numbers, and symbols will offer more security. Also, never write this information down and never carry it in your wallet .

~ Do not reveal any personal information or particularly passwords to anyone.
Don't give your personal and financial information to someone or organizations that you don't know or never dealt with before. Even though giving something, such as date of birth and mother's maiden name, can be used to steal personal identity. Therefore, it's important to know that personal information can be just as dangerous as financial information.

.

~ Be careful of the merchants which you deal with
If you place orders or shop online, try to make sure it is a legitimate site. Transaction made only with good reputation organization, such as Amazon.com. If in the real world, you're shopping, you're more likely to trust an established store that you know and using normal payment means. Besides, it's essential that you use a password-protected and encrypted wallet, to safeguard your credit card information.

.

~ Keep your eye out for scams
Many people have become familiar with common scams. Don’t hesitate, DELETE them. But now there are even more-convincing scam e-mails. You are probably confident you're not getting RM1million from anonymous sources, but if you get an e-mail, where the bank needs you to update your personal information for the security purpose, it looks realistic, Right? People will probably hand over their information and compromise all their financial accounts. If you receive an e-mail from any institution asking for your personal or financial information, even if it appears to come from a place you trust such as eBay, Paypal or Maybank, DO NOT respond. Instead, pick up the phone and call in order to verify. Nowadays, many fake e-mails have been circulating around us. Many people have been a victim of the fake e-mail. PLEASE be cautions! Don’t be one of them.


Sound terrible, right? You don't need to be scared, but you need to be cautious and aware that there are people on the Internet that will take advantage if you allow them. If something doesn't seem right, trust your gut and avoid it.

Related Links:
  1. http://buckeyesecure.osu.edu/SafeComputing/Passwords
  2. http://azlan.anilezfa.com/maybank-fake-email

Posted by Qiao Ling

Thursday, June 18, 2009

History&Evolution of E-commerce










E- Commerce (EC) – the process of electronically buying and selling goods, services and information. EC enables users to communicating, collaborating and discovering information by linked computer systems of the vendor, host and buyer. At the same time, it allows them to do online transaction.

The emergence of EC started in the early 1970s with Electronic Funds Transfer (EFT), which allows organizations to transfer funds with one another electronically.

In the late 1970s, Electronic Data Interchange (EDI) was introduced to improve the limitation of EFT, by extend business transactions from financial institutions to other types of business. Different to EFT( only allow for the transfer of funds), EDI also provides transactions and information exchanges. However, EDI was not widely accepted because the system limited to special networks such as large corporations, and it is costly, complex to administer for small business.

Later, the new type of applications which is Electronic Mail (e-mail) was widely adopted in business world in the late 1980s. When it was first introduced, this system was considered a major breakthrough.

Afterward, a strong foundation of prosperous EC continues to be built. During 1990s, the internet was opened for commercial use. At the period as well, users started to participate in World Wide Web (WWW), and the phenomenon of rapid personal computer (PCs) usage growth. Integrated with the commercialization of the internet, web invention and PC networks, these 3 factors have made EC possible and successful.
There is an important phase in the history of EC that I would like to share with you guys. For your information, there was development of Mosaic web-browser in 1992. This web-browser was soon given the form of a browser which could be downloaded and was named as Netscape. The arrival of Netscape provides users a simple browser to surf the internet. It further broadened the scope and possibility of electronic commercial transaction.

In 1994, Amazon.com (http://www.amazon.com/) and eBay.com (http://www.ebay.com.my/) are examples of internet companies which allows electronic transactions (sell products over the internet). Thanks to their founders! Because of them, we now have the opportunity to enjoy the buying and selling advantages of the internet! In addition, Dell.com (http://www.dell.com.my/) has also contributed much to the process of EC development. It was launched in 1994 and selling goods over the WWW with no retail outlets, no middlemen, and it enables customers to choose the product based on their budget and requirements. With approximately half of the company‘s profit comes from the web sites, the successful of Dell.com has been proven. In that particular year, the internet started to become popular among the general public. However, it took four years to develop the security protocols and DSL, which allowed rapid access and connection to the internet (1998).

What we have discussed above is one of the types of EC – business to consumer (B2C). It was the first and also the most common type which involves e-business providing goods and/or services to end consumers.

In 1999, the emphasis of EC shifted from B2C to business to business (B2B), which is the electronic transaction between multiple businesses, and does not involve common products or consumers.
In 2000, the meaning of the world EC was changed. People began to define the term EC as the process of purchasing of available goods and services over the internet using secure connections and electronic payment services. In the same year as well, the dot com collapse and led to unfortunate results, many EC companies disappeared. But, the “brick and mortar” retailers recognized the advantages of EC and started to add such capabilities to their web sites. At the end of 2001, the largest form of EC, B2B model made $700 billion in transactions.

Web 2.0









Web 2.0 is a second generation of web development and web design. It is characterized as facilitating communication, information sharing, and collaboration on the WWW. It has led to the development and evolution of web-based communities, hosted services, and web applications. Examples include social-networking sites, video-sharing sites, wikis, and blogs. Web 2.0 websites also considered as the Read/Write web, which allow users to do more than just retrieve information. Users can own the data on a Web 2.0 site and exercise control over that data. For example, they are provided with tools to add a comment or to edit the content.

Today, EC is so much better than any other way of shopping that it has already attracted many EC-lovers. People seem to shop literally everywhere – at their workplaces during lunch time, in rush hour, or when there is nothing else to do; they will just switch on their laptops and start surfing. EC today enable us to have a better understanding of product’s shape, size and texture through online. So, why go somewhere out when all you have to do is make an order, choose the shipping method, put up your feet and wait until the order is delivered right up to your door-step?








Posted by shu hui

Revenue model for Google, Amazon.com and eBay

There are billions of websites on the internet. But among these, how many websites actually make money. There is a revenue model that describes how the organization will generate revenue. The major revenue models are sales, transaction fee, advertising, subscription, affiliate and others revenue model.
Google is widely recognized as the world's largest search engine. It is an easy-to-use free service that provides ways to access all this information. Google generates most of the revenue from Google AdWords, Pay per Click Advertising, Google AdSense, Froogle, GoogleAnswers and their latest advertising program which is Cost per Click model. Now, we just focus on the most two common function of Google:
  • Google AdWords is pay per click advertising program. It designed to allow the advertisers to place targeted text-based and display ads on Google web sites and Google Network members’ web sites to people, who are looking for information related to what the advertiser has to offer. Google’s text ads are short, consisting of one title line and two content text lines. When a user searches Google's search engine, ads for relevant words are shown as "sponsored link" on the right side of the screen, and sometimes above the main search results. AdWords advertisers pay Google either based on cost-per-click basis, or cost-per-impression basis.
  • Google AdSense is an online program, where Google distribute advertisers’ AdWords ads for display on the web sites of Google Network members. These ads can generate revenue on either a cost-per-click or cost-per-thousand-impressions basis. AdSense has become a popular method of placing advertising on a website because the ads are less intrusive than most banners, and the content of the ads is often relevant to the website.


Amazon.com is one of successful website that used e-commerce model, where the website sells products or services online. Amazon.com started as an on-line bookstore, and soon diversified into many product lines. Amazon generates revenue primarily by selling books, music, videos, electronics, apparel, and kitchen equipment on domestic. Amazon.com successfully earned distributed transaction fees which are fixed at price through creating virtual marketplace. Moreover, Amazon.com also generates revenue by Affiliate revenue model.Amazon.com is pioneer in affiliate partnership marketing, where uses affiliations with other websites to generate revenue. An Amazon partner website itself may not sell any product or service, but helps in promoting the product. In turn, website owner earns referral fees (commission) on the products purchased by customers. The fee structure is currently the same as for the other affiliate links and ranges from 4% to 10% of the product price.

Ebay is the world's largest auction online marketplace - where practically anyone can sell and bit for practically anything at any time. Millions of collectibles, appliances, computers, furniture, equipment, vehicles, and other miscellaneous items are listed, bought, and sold daily. Ebay does not actually sell goods that it owns itself. It merely facilitates the process of listing and displaying goods, bidding on items, and paying for them. It acts as a marketplace for individuals and businesses that use the site to auction off goods and services. Ebay generates revenue from a number of fees, such as insertion fees, promotional fees, and final value fees. Insertion fees are charged for any item that is listed on Ebay, the fees is nonrefundable, promotional fees are charged for extra listed options that attract attention for an item, while for final value fees are a commission at the end of the auction that is charged to seller. It also earns transaction fee from paypal (Acquired by eBay Inc. in October 2002), an online paying service system for users to buy items online more conveniently as well as advertising fees.

Google, Amazon, and eBay, are few of the most successful e-commerce model that implement different type of revenue model. As we can see that Google earn advertising fee from their advertiser. Whereas Amazon.com’s revenue come from sales throughout their website and collect affiliate fees for referring customers. As for Ebay charged transaction fee on those products listed on their website as well as commissions on any completed auction transaction.


By Qiao Ling

An example of an E-commerce success and its causes

Michael S. Dell founded PC's Limited with capital of $1000 on November 4, 1984. The company was formed when Michael S. Dell was still studying at University of Texas, Austin. PC's Limited beliefs that they could understand the customer's needs by selling products directly to them.

In year 1985, the company sold its the "Turbo PC" for US$795 — which contained an Intel 8088-compatible processor running at a speed of 8 MHz.

The company later change its name from " PC's Limited " to " Dell Computer Corporation " . Trace back to when the company started its business thru Internet, it all back to year 1996 which the company decided to engage in Internet business in selling its products to meet different customer's preferences.

The reasons which contributed to the successful of Dell in the areas of E-Commerce in selling its products are Dell sells their products directly to customers which you cannot find it in any other stores. They also provides services and maintenance of the product to the customers who encounter problems on the product purchased. This has helped to save precious time of the buyer to have their problems fixed. The more important is the buyer can save MONEY !

Another reasons is the Dell's Culture. Dell has created a highly disciplined culture that focuses on optimizing the operational model , responding to what customer wants and needs. Besides, they also provide door to door services to the buyer of their products. Dell respond quick to the commitment of the public and others. Example: if the information of the web outdated even just for minutes, they will fix it within a range rather than waiting for a overall rearrangement.

Dell also one of the low cost providers. Dell know that by being a low cost provider of their product can unlock the hidden business/market opportunities. That's why their product does comes with the balance between quality and money. Unlike Sony Vaio, the high cost of the product does not constitute to a better comparison in cost with Dell.

Despite Product development is focused by the company, the company can allocate resources to the project undergoing. Dell know what kind of R&D they wanted to differentiate their products, this has made the " Dell " can allocate their fund offensively and not defensively.

The customization tools of Dell's Website has made easier for customer to purchase the laptop or PC and any other products in just few clicks. WoW... it's never been easier for the customer !

The above are the reasons contributed to the success of DELL.

Related Links:

1.http://www.oppapers.com/essays/Dell-Key-Success-Factors/150188

2.http://en.wikipedia.org/wiki/Dell







Posted by Chee Liat Long