Labels

Sunday, 28 June 2009

The application of 3rd party certification programme in M'sia

Posted by Thomas Wong


TrustGate is the most popular application of 3rd party certification programme in Malaysia. It was established in 1999 as a licensed Certification Authority (CA) in Malaysia under the Digital Signature Act 1997 and operating within the Multimedia Super Corridor. It provides security solution and trusted services to help companies build a secure network and application infrastructure for their electronic transactions and communications over the network. Security is the basic concern of entering into the new Internet economy. The ever-changing paradigm of e-commerce needs a well-mandated safety infrastructure. The vision of Trustgate.com is clear: “To enable organizations to conduct their business securely over the Internet, as much as what they have been enjoying in the physical world.” http://www.trustgate.com/
Now, I would like to introduce two main services that are provided by TrustGate.com

1)MyTrust for Mobile Signature
With MyTrust, you can turn a SIM card into a Mobile Digital Identity for secure mobile banking and other financial services. Mobile digital signature provides non-repudiation on transactions under the Digital Signature Act, 1997. It runs on Wireless PKI platform and Mobile Operator infrastructure. PKI-enabled SIM cards are preloaded with MyTrust application and a digital certificate from a licensed Certification Authority. Users are able to digitally sign any transaction with ease and convenience via their mobile phone.




2)MyKad PKI (MyKey)
Malaysian government has put in place a smart National Identity Card (“MyKad”) for every citizen. MyKad with PKI capability allows its holder to conduct online transaction with government agencies and private sectors. MyKey, is the MyKad PKI solution that works with your physically MyKad, allowing you to authenticate yourself online and to digitally sign documents or transactions and is accepted by the Malaysian government.







Trustgate is a very popular and useful 3rd party certification programme in Malaysia today. By using Trustgate, we are able to secure our online transactions and data more efficiently. But frankly, 3rd party certifucation programme is still not common in Malaysia, because the citizens here are still lacking of understanding about online security. Hence, I do hope to have more certifications to be founded in malaysia in order to promote a safer internet world.

Saturday, 27 June 2009

Phishing: Example and its prevention methods

Posted by Edmond Chong



Add VideoA brief history on “Phishing”
The word phishing comes from the analogy that Internet scammers are using e-mail lures to fish for passwords and financial data from the sea of Internet users. The term was coined in 1996 by hackers who were stealing AOL Internet accounts by scamming passwords from unsuspecting AOL users. Since hackers have a tendency to replacing "f" with "ph" the term phishing was derived.


Definition of “Phishing”
Phishing is defined by Wikipedia as the criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication. Communications purporting to be from popular social web sites, auction sites, online payment processors or IT Administrators are commonly used to lure the unsuspecting public. (http://en.wikipedia.org/wiki/Phishing)

In layman terms, it is the act of sending an e-mail to a user falsely claiming to be an established legitimate enterprise in an attempt to scam the user into surrendering private information that will be used for identity theft. The e-mail directs the user to visit a Web site where they are asked to update personal information, such as passwords and credit card, social security, and bank account numbers, that the legitimate organization already has. The Web site, however, is bogus and set up only to steal the users’ information.

Example of how “Phishing” works























1. This is a false claim disguising as though it is sent by Citibank.

2. They might include a graphic from the bank right on the email message or website. The logo of Citibank further mislead the customers believe this e-mail is truly sent by Citibank.

3. Lastly, directing/leading people to click on the link provided (any clickable links) in the e-mail to theft information. The link provided may look like it goes to the bank’s website while the victim is actually sent to a very different site.

Generally, this is how “phishing” works.

Phishing prevention methods
Here's some simple yet effective methods to avoid being scammed.

1. Check who the email is from - This is an extremely effective and easy way to stay safe. Just check the sender of the email. If the email address is not the domain of a legitimate bank/service, then it is certain that it is a phishing scam. Also, be aware of banks or institutions that send you an email saying you need to verify your account information, and it’s a place you don’t even do business with! Simply delete any emails like these.

2. Do not follow a click here link in the email - Phishing emails usually have a “Click here to re-enter your user information” kind of link that leads to an illegitimate website. This is not fool-proof. Just by looking at the link, you may be able to determine whether the link is the real deal. Also, do not just focus on the domain; take a look at all the slashes that follow. Also, make sure that if there is a copy-and-paste link that the one that is embedded is the same likes the one written.

Furthermore the connection should be encrypted – the link should start with https:// instead of http:// . Don’t click the link in the email thinking you will set them straight. Instead, you would have just fallen into their trap by letting them have your information.


3. Check contact information provided in the email - A lot of Phishing emails contain bogus contact information that would just serve you into their hands. In case you get an email with a phone number or an address, check that against the one that you got when opening the account. If they are not the same the email is a scam.


4. Check the information about you provided in the email - Perpetrators are getting better and better at obtaining your information. Just because they know your name does not mean that the email is legit. They could have gotten that from any social networking website. Instead, if there is any other information provided, such as an account number, make sure it corresponds to what you have.

5. Use your browser - All newer browsers have some sort of website identification mechanism that allows you to check the identity of the site. “Real” websites will have that information… while those set up solely for the purpose of farming information will not.

Why would somebody do this? Well, you can gather a lot of juicy information with a phishing scam. First, you can get somebody’s account number and password. Then you can try to hijack their assets. Some phishing scams ask for all of your personal information so that they can steal your identity and open credit accounts in your name.

Thus, users have to becareful to avoid falling for phishing scams. These methods above are sufficient to prevent most of the common phishing scams on the internet. There shouldn't be any problem if users follow these advices and methods accordingly.

Anyone would like to know more about phishing, how to spot phishing scams and other related articles may visit at http://banking.about.com/od/securityandsafety/a/phishingscams.htm for more information.

Friday, 26 June 2009

How to Safeguard our Personal and Financial Data

Posted by VIVA


Internet, is a public network without any restrictions and connecting millions of computer throughout the world. But, when we are signing up for some registrations, we need to fill in personal information like gender, DOB, addresses, e-mail address and others. The information that entered will be kept by the particular company in their database.

For example,
When we are make an online purchase, we need to do an online payment. The moment we key in our credit card numbers or other personal data on the websites, how sure are we that our information will be confidential, safe and secure?
Why do we need to protect our personal and financial data? Major security issues are authentication, authorization, auditing, confidentiality, integrity, availability, and nonrepudiation. The main reason is to prevent unauthorized access of hackers or crackers that will bring harm or losses. (http://en.wikipedia.org/wiki/Hacker_(computer_security, http://en.wikipedia.org/wiki/Hacker_(computer_security)#Black_hat)



How to safeguard our personal and financial data in the Internet, the public network? Some of the most often used methods to safeguard your personal data and financial data are:-


1. Authentication System
Authentication system identifies the legitimate parties to a transaction and determines the actions they are allowed to perform. This system also limits their action to only those that are necessary to initiate and complete the transaction. It included.

· Access control mechanism – limits the actions that can be performed but an authentication person or group.
· Passive tokens – storage devices (e.g. magnetic strips) used in a 2 factor authentication system that contain a secret code.
· Active tokens – small, stand-alone electronic devices in a two factor authentication system that generate one-time password.
· Biometric systems – authentication system that indentify a person by measurement of a biological characteristic such as fingerprint, iris pattern, facial features or voice.

2. Public key infrastructure (PKI)
A scheme for securing e-payment using public key encryption and various technical components.

3. Private and public key encryption
Encryption is the process of scrambling a message in such a way that is difficult, expenses, one time consuming for an unauthorized person to unscramble it.
· Symmetric (private) key system
An encryption system that uses the same key to encrypt and decrypt the message
· Asymmetric (public) key encryption
Method of encryption that uses a pair of matched keys – a public key to encrypt a message and a private key to decrypt it, or vice versa.

4. Digital signature and certificates
· Digital signature
an identifying code that can be used to authenticate the identity of the sender of a document
· Hash
a mathematical computation that is applied to a message, using a private key, to encrypt the message.
· Message digest
a summary of a message, converted into a string of digits, after the hash has been applied.
· Digital envelope
the combination of the encrypted original message and the digital signature, using the recipient’s public key
· Digital certificate
Verification that the holder of a public or private key is who they claim to be
· Certificate authorities (CAs)
Third parties that issue digital certificates

5. Secure socket layer (SSL)
Protocol that utilizes standard certificates for authentication and data encryption to ensure privacy or confidentiality

6. Secure electronic transaction (SET)
A protocol designed to provide secure online credit card transactions for both consumers and merchants; developed jointly by Netscape, Visa, MasterCard, and others

7. Firewall
Software application that acts as a filter between a company’s private network and the Internet

Good security is just plain good business. Aware of the risk of identity theft, today’s customers are concerned about their privacy. All business owners know that customers prefer companies that demonstrate commitments to security. For the same reasons, customers will think twice before doing business with a company that has got less experience on privacy issues.

Monday, 22 June 2009

The threat of online security: How safe is our data?

Posted by jimmy
















Nowadays, people rely on computers to create, store and manage critical information. Consequently, it is important for users to aware that computer security plays a major role in protecting their data from loss, damage, and misuse. The threat of online fall under several general categories: (1) accidental actions (2) malicious attacks. Within this latter category there are numerous subgroups, including computer viruses, denial of service attacks and distributed denial of service attacks. (3) online fraud, comprises issues such as identity theft and data theft.

1. Accidental actions
Accidental actions contribute to a large number of computer security risks. This category encompasses problems arising from basic lack of knowledge about online security concepts and includes issues such as poor password choices, accidental or erroneous business transactions, accidental disclosure, and erroneous or outdated software.

2.Malicious attacks
Attacks that specifically aim to do harm are known as premeditated or malicious attacks. They can be further broken down into attacks caused by malicious code and those caused by intentional misrepresentation. The most common form of malicious code is a computer virus. There are four main classes of viruses which are file infectors, system or boot-record infectors, macro viruses and multi-part viruses.(http://www.inc.com/articles/2000/04/18782.html).
At the 2009, there are some top 100 malicious that everyone can have a look.
(http://www.pcpitstop.com/libraries/process/topmalicousmalicous)

Denial of service attacks, another form of malicious code, are carefully crafted and executed. Denial of Service Attacks are not new, yet they are growing in sophistication. Traditional DOS attacks usually involve one computer attacking another, but the use of multiple computers in a highly organized attack is becoming increasingly common. Such attacks, known as Distributed Denial of Service attacks (DDOS), were witnessed in a number of large corporate computer shutdowns in 2000. The DDOS attacker strategically builds an army of key players including one client machine for coordinating the attack and three to four host machines which are battlefields under the attacker's direct control.
(http://en.wikipedia.org/wiki/Denial-of-service_attack)





















3. Online fraud
















Online fraud is a broad term covering Internet transactions that involve falsified information. Some of the most common forms of online fraud are the sale via Internet of counterfeit documents, such as fake IDs, diplomas, and recommendation letters sold as credentials.



















Identity theft is a major form of online fraud, or misrepresentation. Personal identity theft on the Internet is the newest form of fraud that has been witnessed in traditional settings for many years. For example, in traditional settings, thieves open credit card accounts with a victim's name, address and social security number, or bank accounts using false identification. In the online world, electronic commerce information can be intercepted as a result of vulnerabilities in computer security. Thieves can then take this information (such as credit card numbers) and do with it what they will. (http://www.cifas.org.uk/default.asp?edit_id=561-56)

Identity theft can also be undertaken on a large scale, as in the case of a company or even a city. For example, in January 2001, the entire municipality of Largo, Florida lost e-mail service for over a week when an unknown company based in Spain compromised its identity. The company hacked into the city's e-mail relay system to steal the Largo.com identity. Soon enough, e-mail spam seemingly from Largo.com addresses flooded the net, and many Internet Service Providers blacklisted all incoming and outgoing electronic messages from the city.

No one connected to a computer network is really safe from hackers. Fortunately, most invasions or infections don't result in serious injury to the system that has been attacked, provided that you have an ongoing backup plan. In the end of this topic blog, here are some my advises about security prevent methods to protect your computer system:

1.Erect a firewall between the Web server and your network.
2.
Place e-mail virus scanners on all computers.
3.Hire a skilled system administrator.
4.Keep up-to-date with security patches for your operating system and server software.
5.Remove unused communication ports.