Wednesday, February 11, 2009

The application of 3rd party certification programme in Malaysia







The most famous application of 3rd party certification program in Malaysia is provided by the MSC Trustgate.com Sdn Bhd. MSC Trustgate.com Sdn Bhd was incorporated in 1999 and is a licensed Certification Authority (CA) under the operation of the Multimedia Super Corridor. Certification Authority is the body given the license to operate as a trusted third party in the issuance of digital certificates.

The objective of MSC Trustgate is to secure the open network communications from both locally and across the ASEAN region. Trustgate provide digital certification services such as digital certificates, cryptographic products and software development. The products and services of Trustgate are SSL Certificate, Managed PKI, Personal ID, MyTRUST, MyKAD ID, SSL VPN, Managed Security Services, VeriSign Certified Training and Application Development. The vision of Trustgate is to enable organizations to conduct their business securely over the internet, as much as what they have been enjoying in the physical world.

Trustgate offer the following SSL certificate for our service security:

i)Global Server IDGlobal Server ID adopts today's strongest encryption commercially available for secure communications via Server Gated Cryptography (SGC) technology. GSID authenticates your web sites and enables 128- or 256-bit encryption to secure communications and transactions between the site and its visitors. Every purchase of GSID comes with a VeriSign Secured Seal that you can display on your web site. The seal is an instant proof that your web site is genuine because you have been verified by the World Leader of SSL Provider, and your customers can conduct business with you free of worry.

ii)Secure Server IDSecure Site SSL Certificates protect the transfer of sensitive data on Web sites, intranets, and extranets using a minimum of 40-bit and up to 256-bit encryption. It includes VeriSign Secured Seal.

Electronic Currency

Electronic Currency



Electronic Currency also known as e-money, electronic cash, electronic money, digital money, digital cash or digital currency. Actually, electronic currency is refers to money or scrip which is exchanged only electronically. It is involves use of computer networks, the internet and digital stored value systems. For examples: Electronic Funds Transfer (EFT) , direct deposit and etc. It is also a collective term for financial cryptography and technologies enabling it.


Electronic Currency Trading System (ECTS)

ECTS is an electronic currency trading investment platform that offers its clients an efficient way to trade foreign currencies against the strength and weakness of the US dollar. Utilizing its database of historical price patterns and technical indicators, the complex algorithms interwoven into the system allow for the recognition of entry positions with maximum profit potential.
In order to maintain prudent money management, 24-hour stops are put in place to lock in gains as well as prevent heavy losses. There has never been a better time to invest in currency trading than right now.

ECTS Trades the 6 Major Currencies

1. Euro,
2. Yen,
3. Australian $,
4. Canadian $,
5. Swiss Franc
6. British Pound.

It attempts to capture longer term moves, and is not a day-trading system. All currencies are traded on the regulated markets of the Chicago Mercantile Exchange. Generally all Exchange fees are public. Spreads are consistently tight.
As opposed to many mechanical trading systems, which always seem to lack an “ingredient” such as a stop-loss, or a trailing stop, this system has all the elements that a trader might seek in a mechanical trading system.
ECTS is not a mystery system; anyone who purchases the system has full access to the inputs and logic.

Digital currency exchangers (DCE)

Digital currency exchangers (DCEs, independent exchange providers or e-currency exchangers) are market makers which exchange fiat currency for electronic money, such as digital gold currency (DGC), and/or convert one type of digital currency (DC) into another, such as WebMoney into e-gold. Exchangers apply either a commission or bid/offer spread to transactions.

Saturday, February 7, 2009

The Threat Of Online Security:How safe is our data...

Nowadays, the technology at internet is continue grow rapidly, so that everyone also can easily to access to the internet. People rely on computers to create, store and manage critical information. Consequently, it is important for users to aware that computer security plays a major role in protecting their data from loss, damage, and misuse.

There are some websites are not so safety for the users to use this is because some people are created some malicious program such as computer viruses, worms, trojan horses and spyware. So, let us to discuss the threat of online security:

(i) Computer Viruses
Computer viruses is a piece of software code that inserts itself into a host which including the operating systems to spread over and harm the users computer. In the internet world, there have around 80,000 viruses and everyday will have 25 new viruses be created. The examples of computer viruses are I Love You virus, AutoRun and etc.

How Does A Virus Or Worm Infection Affect Us?
Unfortunately, the effects of an infection are pretty unpleasant. The virus or worm, can,

  • Disable the computer
  • Add, modify or delete files or reformat the hard disk
  • Steal addresses held in our computer to send on virus-infected emails to our friends, colleagues, clients or customers
  • Send unsolicited bulk email (spam) to those in our mail address books and other users

(ii) Trojan Horses
Trojan horses are a program that appears to be useful but actually is the mask destructive program. The example of Trojan horse is Trojan Xombe which is the mask as email from Microsoft. The hackers will access to the computer and steal the passwords.

How Does A Trojan Infection Affect Us?

A Trojan installed on a computer allows that PC to be entered via a 'backdoor' by any remote user that has the access code to the Trojan.

The remote attacker can enter the computer undetected, when the user is online, to access or destroy any information stored. Alternatively, the Trojan can be programmed to automatically send any information on our PCs back to the attacker. This could include,

  • Client or customer information or other business data
  • Credit card details
  • Passwords for access to your online bank, ISP or web services
  • Information you would rather remain hidden
  • Email addresses, which may be used for spamming
  • Children's names, photographs, ages or other personal details held on the computer
  • Distributed Denial of Service (DDOS) attack on other computers via the victim's computer

(iii) Spyware
Spyware is the software that gathers user information through the user’s Internet connection without the user knowledge.

How Does Spyware Affect Us?

Surveillance or monitoring spyware can scan our hard drive and search programs for sensitive information like credit card, bank information and personal details.

It can change our browser's home page, scan browser history for web sites visited and monitor various aspects of our computer and Internet activity! The information is then transmitted to the attacker.

More and more companies are installing spyware to watch us at work to check that we are not using the company network to surf prohibited sites or spending too much time dealing with personal email.


Friday, February 6, 2009

How To Safeguard Our Pesonal And Financial Data




I believed all of you are know what is internet ,right? Nowadays, internet is commonly in use. A lot of transaction will be done via internet, and so there always has a risk of theft of our personal and financial data. Most of the website has provided the privacy and security to user, such as: Secure Socket Layer (SSL), require password customization, monitor industry standards and etc. Although, data stolen cases are still increasing in our society nowadays. Therefore,we need to protect and safeguard our personal and financial data against misuse or theft by others. Below will be some suggestion ways to share with you to safeguard your data:
1)Password protect: use a strong password or pass-phrase to protect your access data.
2)Secure your computer. If you manage your accounts online, make sure that your computer has up-to-date spyware, antivirus protection, and firewall software—and that you use it.
3)Protect your Social Security number. Store your card in a safe place and avoid giving the number to others.
4) Install a firewall: a firewall is a software program designed to allow good people in and keep bad people out. Most new computers come with firewalls integrated into their operating systems. If you have an older computer or using dial-up, you may need to buy a firewall separately and install it yourself.
5)Pay attention when using an ATM and keep your eyes peeled for anyone who seems a little too interested in your transactions. Use your free hand to shield the keypad when entering your PIN. Besides that, banker can add on fingerprint scanning on ATM machine.
6)Never give out your personal information like Social Security number, date of birth, mother's maiden name, credit card number over the telephone unless you initiated the call to a trusted organization.
7)Don't reply to requests for personal information. Never reply to, or click a link in, an unsolicited e-mail. Nor should you give out personal information over the phone if you didn't initiate the call.
Even thought the internet is very convenient to us but it is really a need to protect our personal and financial data against any losses.
related link:
http://www.us-cert.gov/cas/tips/ST06-008.htmlus-cert.gov/cas/tips/ST06-008.html

Thursday, February 5, 2009

Phishing: Examples and its prevention methods

What is phishing?

Phishing is the criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication. Phishing is carried out by e-mail or instant messaging, and it often directs users to enter details at a fake website whose look and feel are almost identical to the legitimate one. Phishing is an example of social engineering techniques used to fool users , and exploits the poor usability of current web security technologies. Attempts to deal with the growing number of reported phishing incidents include legislation, user training, public awareness, and technical security measures.


Examples of phishing email

Ex1:

From: Chase Online

Sent: Friday, November 28, 2008 10:14 AM

Subject: WaMu & Chase. Safe & Secure - Message id XLKLTRZBGW

WaMu customers: we're proud to welcome you to one of the nation's largest banks; as of September 25, 2008, all WaMu customer deposits are now deposits of JPMorgan Chase, one of the most stable banks in America.
What will change;
Some aspects of the ONLINE SERVICES: Chase Online and WaMu Online
DEADLINE: December, 30, 2008
What you need to do:
Update your information by visiting Chase Online or WaMu Online. Log on to your account and you will be re-directed to the client information update screen.

If you have not signed up for online access, you can enroll easily by clicking "Enroll" at the bottom of the Login page.

Please do not reply to this message. For questions, please call Customer Service. We are available 24 hours a day, 7 days a week.

Sincerely,
Carter Franke
Chief Marketing Officer
Member Services

This site is directed at persons in the United States only. Persons outside the United States may visit International Banking.

Links to third party sites are provided for your convenience by JPMorgan Chase. JPMorgan Chase neither endorses nor guarantees any offerings of the third party providers, nor does JPMorgan Chase make any representation or warranty of any kind about the content, use of or inability to use, the third party sites.

©2008 JPMorgan Chase & Co


Ex2:

From: survey@survey.chase.com
To: Recipient
Sent: 11/21/2008 8:17:54 A.M. Eastern Standard Time
Subject: Customer Satisfaction Survey

Dear Chase client,

Due to the rumors of financial crisis, Chase has decided to make a nationwide survey. The information collected will be used to improve our services and your banking experience with us. For the completion of this survey, we will credit your account with $100.

To take part, please click here.

Note - The information we gather from this survey will not be handed down to any third party.

© 2008 JPMorgan Chase & Co.

Ex3:

To: Recipient

Subject: Add 50$ to your account in 2 minutes!

Dear Customer,

You are invited to take part in our nation-wide 5 question survey. Your time is very important to us so $50 will be credited to your account upon the completion of this survey.

Please note that no sensitive information will be required, collected or stored. The information will be used to further improve our services.

To take part please click here.

© 2008 JPMorgan Chase & Co.



Methods to prevent phishing

Keep Your Email and Instant Message Addresses Private

Better prevent them from landing in your email box in the first place. You may find it useful to have a separate email address for financial institutions, one for trusted friends and family, and one for general or public use. Many email providers will allow you to redirect emails from each of these different addresses to one account to minimize the inconvenience of checking each account. Do everything possible to keep the address you use for financial transactions as private as possible.

Immediately Report Suspected Phishing Contacts

If receive a message that are suspect , call the customer service phone number right away to confirm whether you've received an actual message or not. In addition, almost every bank and credit card lender has a website where you can report suspicious emails and instant messages.

Limit Your Dialogue

The phishing perpetrators might encourage you to communicate with them and attempt to play mind games with him or her. So, the best thing you can do is simply report their activities and move on with your life.

In many cases, almost all of these messages are automated - so attempting to play mind games only leads to more frustration on your part. Just keep reporting them to your bank and the FBI, if necessary. While you may be tempted to send along a nasty letter to the perpetrator, it is better to simply set up a spam blocker and try to ignore them.

When you are threatened with the loss of access to a bank account, it may be very easy to justify giving up sensitive information. The best thing you can do is report anything you suspect as phishing and let the bank and the authorities manage it from there.

How E-commerce can reduce cycle time, improve emplyees' empowerment and facilitate customer..

Cycle Time

Cycle time is the total time from the beginning to the end of your process, as defined by you and your customer. Cycle time includes process time, during which a unit is acted upon to bring it closer to an output, and delay time, during which a unit of work is spent waiting to take the next action.

In a nutshell - Cycle Time is the total elapsed time to move a unit of work from the beginning to the end of a physical process.
E-commerce can reduce cycle time by making the sales process across the internet between dealers and customers. Dealers can create their own web page to display their goods and services accordingly for customer to surf and refer. So, if the customers want to buy it can just take the order through internet easily. Then, the dealers can just delivery the goods or provide the services to the customers in a short time. So, dealers and customers can save cost and time through e-commerce.

Employee empowerment is a term used to express the ways in which non-managerial staff can make autonomous decisions without consulting a boss. These self-willed decisions can be small or large depending upon the degree of power with which the company wishes to invest employees. Employee empowerment can begin with training and converting a whole company to an empowerment model.

To begin employee empowerment in the workplace is to install a suggestion box, where workers can make suggestions without fear of punishment or retribution. Managers must then be willing to read and consider suggestions. They might provide a forum where questions or suggestions. In addition, managers can hold a once monthly meeting open to employees where all suggestions are addressed. In another hand, if employees gain the authority to make decision can help increase customers confident. Besides that, employee empowerment can also help to unlock the employee potential and create employee loyalty.

Customer Support

Customer service (also known as Client Service) is the provision of service to customers before, during and after a purchase. On the others side, Customer service is a series of activities designed to enhance the level of customer satisfaction – that is, the feeling that a product or service has met the customer expectation. Its importance varies by product, industry and customer. As an example, an expert customer might require less pre-purchase service (i.e., advice) than a novice. In many cases, customer service is more important if the purchase relates to a “service” as opposed to a “product". Customer service may be provided by a person, or by automated means called self-service. Examples of self service are Internet sites.

Internet provides 7/24/365 day to connect with the customer as well as provide the customers services. It is easily for customers to gain the related information in anytime and at anywhere that customers want. Besides that, Computer can help to store the information of customer and therefore help the company to better understand of the customer need.

Tuesday, February 3, 2009

The history and evolution of E-commerce





Electronic commerce, commonly known as e-commerce .It consists of the buying and selling of products or services over electronic systems such as the Internet and other computer networks.
In the early development, the meaning of electronic commerce has changed over the last 30 years. Originally, electronic commerce meant the facilitation of commercial documents like purchase order or invoices electronically. The growth and acceptance of credit cards, automated teller machines (ATM) and telephone banking in the 1980s were also forms of electronic commerce. From the 1990s onwards, electronic commerce would additionally include enterprise resource planning systems (ERP), data mining and data warehousing.
Although the Internet became popular worldwide in 1994, it took about five years to introduce security protocols allowing continual connection to the Internet. And by the end of 2000, a lot of European and American business companies offered their services through the World Wide Web.
E-Commerce was birth out of the World-Wide-Web (WWW). Although many people use the terms WWW and Internet interchangeably, the WWW is just one of the many services available on the Internet. While the Internet was developed in the late 1960s, the WWW came into existence more than a decade ago. Since then, however, it has grown phenomenally to become the most widely used service on the Internet.Although the Web has made online shopping possible for many businesses and individuals, in a broader sense, e-commerce has existed for many years. For decades, banks have been using electronic funds transfer (EFT),which are electronic transmissions of account exchange information over private communication networks. Businesses also have been engaging in a form of electronic commerce, known as electronic data interchange (EDI), for many years.
Indeed, e-commerce has evolved from online billboards to a fully functional, personalized shopping experience over the past decade. While there were admittedly a few bumps along the road, the path from 1994 through the 2004 holiday shopping season is full of crucial milestones of Internet pioneers and technology innovators.