Wednesday, February 11, 2009

Electronic Currency


Banks have been able to move currency electronically for decades, only recently that the average consumer had the capability to use electronic transfers in any meaningful way. With the advancement in technology and more computer savvy individuals, global interaction is made available at vastly reduced costs. The Internet and E-commerce have become an increasingly commercial area, where daily payments are rendered for goods, information, services and investment. As a result, electronic payments are becoming the central part to online business between customer and seller.

Electronic money refers to digital currency that you can use on the Internet to buy and sell goods, services and investments by transmitting a number from one computer to another, where it typically involves use of computer networks, the Internet and digital stored value system. These transactions are carried out electronically, transferring funds from one party to another, by either a debit or credit. These funds are instantly cleared and secured by using strong encryption, thus eliminating the payment risk to the consumer.

One major type of Electronic money is the Integrated Circuit Card (ICC). ICC could be broken down further into 2 types - Contact ICC and Contactless ICC.

Contact ICC


Contact smart cards have a contact area, comprising several gold-plated contact pads, that is about 1 cm square. When inserted into a reader, the chip makes contact with electrical connectors that can read information from the chip and write information back. The cards do not contain batteries; energy is supplied by the card reader.

Examples of Contact ICC's:
  1. Credit cards
  2. Malaysian MyKad
  3. ATM cards

Contactless ICC



The chip communicates with the card reader through Radio Frequency Identification (RFID) induction technology (at data rates of 106 to 848 kbit/s). These cards require only close proximity to an antenna to complete transaction. They are often used when transactions must be processed quickly or hands-free, such as on mass transit systems, where smart cards can be used without even removing them from a wallet.

Examples of Contactless ICC's:
  1. Hong Kong's Octopus Card
  2. Malaysia's Touch n Go Card
  3. San Diego's Compass Card

Advantages of E-Currency

Flexibility


There is no need, for example, to carry several cards: one card can simultaneously be an ID, a credit card, a stored-value cash card, and a repository of personal information such as telephone numbers or medical history. Such a card can be easily replaced if lost, and, because a PIN number (or other form of security) must be used to access information, is totally useless to people other than its legal bearer. At the first attempt to use it illegally, the card would be deactivated by the card reader itself.

Security

They are encryption devices, so that the user can encrypt and decrypt information without relying on unknown, and therefore potentially untrustworthy, appliances such as ATMs. ICC's are very flexible in providing authentication at different level of the bearer and the counterpart. Finally, with the information about the user that ICC's can provide to the other parties, they are useful devices for customizing products and services.

Other general benefits of sICC's are:
  • Portability
  • Increasing data storage capacity
  • Reliability that is virtually unaffected by electrical and magnetic fields.

Limitations of ICC's


Security


VISA and MasterCard developed a new standard, SET, in early 1996 in an attempt to get the entire industry on a standard of encryption. Additionally, there are standards such as DES which have been around for years, usable in all forms of encryption which are being used in ICC's. But still some ICC's are not inviolate. Mondex, a maker of banking ICC's, solves this problem by making its transactions possible only between Mondex cards. But in order for ICC's to reach their full potential, they must be able to interact with a host of interfaces. And they must do so securely.

Public Perception

People must believe that the cards are secure. This depends to a great extent upon actual security, but people must also be convinced of it. And once people are comfortable that the card is secure, they must still be confident that a stalker isn't somewhere collecting and analyzing all of the information gleaned from the ICC's use.

Product Complements

While ICC's themselves are fairly cheap, card readers are not. However, in an effort to make ICC's more pervasive, companies such as Netscape and Microsoft are proposing putting software in packages they make. Additionally, Gemplus has created a new pocket reader and other companies are considering adding readers to keyboards.

Friday, February 6, 2009

Phishing: Examples and its prevention methods.


What is Phishing and its Examples.
Phishing is a scam in which the attacker sends an email purporting to be from a valid financial or eCommerce provider, which generally looks and feels much like the valid eCommerce or banking site.
Often phishing spam messages will use legitimate 'From:' email addresses, logos, and links to reputable businesses such as Citibank, PayPal, eBay in the message. But the message instructs you to click on a web link that sends you to a fake website where you are asked to provide personal information such as your name, address, phone number, date of birth, and bank or credit card account number. Providing this kind of information can leave consumers at risk for identity theft.

We may see the phishing scam in the e-mail messages, social networking website, fake website that accepts donations for charity, instant message program and even on your cell phone or other mobile devices.

Fake, copycat Web sites are also called spoofed Web sites. They are designed to look like the legitimate site, sometimes using graphics or fonts from the legitimate site. They might even have a Web address that's very similar to the legitimate site you are used to visiting.

These are few examples of phishing scams:
This PayPal phishing scams tries to trick recipients by pretending to be some sort of security alert. Claiming that someone 'from a foreign IP address' attempted to login to your PayPal account, the email urges recipients to confirm their account details via the link provided.

The attacker claims to be acting in the interests of safety and integrity for the online banking community. Of course, in order to do so, you are instructed to visit a fake website and enter critical financial details that the attacker will then use to disrupt the very safety and integrity they claim to be protecting.

This eBay phishing email includes the eBay logo in an attempt to gain credibility. The email warns that a billing error may have been made on the account and urges the eBay member to login and verify the charges.

Prevention Methods
It is easy to uncover a crude phishing scam. For example, if you get an email from a bank you’ve never opened an account at, then don’t follow the link and enter your personal information. Now, if you actually have an account at the institution it gets more interesting.
Besides that, user must avoid filling out forms in e-mail messages. You can't know with certainty where the data will be sent and the information can make several stops on the way to the recipient.
If you click on a link in an e-mail message from a company be aware that many scam artists are making forgeries of company's sites that look like the real thing. Verify the legitimacy of a web address with the company directly before submitting your personal information.

Here are some common phrases where e-mail message or phone message may be a phishing scam:

"Verify your account."
Businesses should not ask you to send passwords, login names, Social Security numbers, or other personal information through e-mail.
"You have won the lottery."
The lottery scam is a common phishing scam known as advance fee fraud. One of the most common forms of advanced fee fraud is a message that claims that you have won a large sum of money, or that a person will pay you a large sum of money for little or no work on your part. The lottery scam often includes references to big companies, such as Microsoft.
"If you don't respond within 48 hours, your account will be closed."
These messages convey a sense of urgency so that you'll respond immediately without thinking. A phishing e-mail message might even claim that your response is required because your account might have been compromised.

The best way to avoid becoming a phishing scam victim is to use your best own adjustment. No financial institution with any sense will email you and ask you to provide all of your sensitive information. In fact, most institution are informing customers that “ we will never ask you for your personal information via phone or email.

Thursday, February 5, 2009

The Application of 3rd Party Certification Program in Malaysia


Third party certification is an assessment carried out to ensure compliance with a publicly available technical specification. Importantly, the assessment is carried out by an independent, third party organization that is qualified and licensed to issue certification when the assessment is successfully completed.

This means that rather than an organization or company claiming to comply with industry standards, they have taken their commitment to quality further and invited in an external third party to verify that their product or service does indeed comply with the industry standards.

The most popular application of 3rd party certification in Malaysia is provided by the MSC Trustgate.com Sdn. Bhd. MSC Trustgate.com Sdn Bhd is a licensed Certification Authority (CA) operating within the Multimedia Super Corridor. MSC Trustgate was incorporated in 1999 to meet the growing need for secure open network communications and become the catalyst for the growth of e-commerce, both locally and across the ASEAN region.

Trustgate is licensed under the Digital Signature Act 1997 (DSA), a Malaysia law that sets a global precedent for the mandate of a CA. As a CA, Trustgate’s core business is to provide digital certification services, including digital certificates, cryptographic products, and software development. It provides security solutions for individuals, enterprises, government, and e-commerce service providers using digital certificates, digital signatures, encryption and decryption as this is the primary concern of entering into the new Internet economy.

Among the products and services that they provide are Secure Sockets Layer (SSL) Certificate Authority, Managed PKI, Personal ID, MyTRUST, MyKad ID and etc. In addition, MSC Trustgate has been appointed as Asia's first VeriSign Authorised Training Centre. Under this partnership, MSC Trustgate.com and APIIT (Asia Pacific Institute of Information Technology) jointly facilitate the delivery of VeriSign’s high-end Security and E-Commerce programmes. VeriSign is the leading Secure Sockets Layer (SSL) Certificate Authority which also enabling the security of e-commerce, communications, and interactions for Web sites, intranets, and extranets. It provides security solutions to protect an organization’s consumers, brand, Web site, and network.


The Diagram below shows how Verisign tackle spamming and it's solutions:


Therefore, it is important to apply 3rd certification programme as it provides a safe and secure Internet protection. More e-consumer can now shop and purchase online care-free while their personal information or confidentiality is protected

.

The threat of online security: How safe is our data?


Do you truly believe that your data is safe? You might think so. Unfortunately, there are threats online that keep knocking on your door until you let them in - intentionally or not. Once they are in your computer system, they will cause havoc and may result in you losing all your data.

Therefore, online security has become an enormous concern when surfing the net. And with good reason. These threats to online security may cripple your computer system and halt business activities which means losing precious data and time. Besides that, these threats evolve over time and always find a way to better the security softwares we have installed in our computer systems. Therefore, there is always a need to update security softwares to keep our data safe from these threats.

The following are some of the threats to online security:

Malware


A MALicious softWARE or malware constitutes any software written for malicious reasons that infiltrates a computer without authorization and performs some nefarious function. Malware can come in many varieties and perform a myriad of functions. it is this carefully engineered software that performs attacks on an automated level among millions of compromised machines around the world, that makes it the centerpoint of the modern cybercrime landscape. Malware includes computer viruses, worms, trojan horses, most rootkits, spyware, and other malicious and unwanted software.

Botnets


A roBOT NETwork or botnet is a huge number of hijacked Internet computers that have been set up to forward traffic, includig spam and viruses, to other computers on the Internet. The computer is compromised via a Trojan that often works by opening an Internet Relay Chat (IRC) channel that waits for commands from the person in control of the botnet. The very nature of botnets gives criminals plenty of power on the internet at large. With control over so many compromised systems, herders can now engage in quite more damaging activities than the internet has seen before.

Virus


Computer viruses are small software programs that are designed to spread from one computer to another and to interfere with computer operation. A virus might corrupt or delete data on your computer, use your e-mail program to spread itself to other computers, or even erase everything on your hard disk.

Viruses are most easily spread by attachments in e-mail messages or instant messaging messages. That is why it is essential that you never open e-mail attachments unless you know who it's from and you are expecting it. Viruses can be disguised as attachments of funny images, greeting cards, or audio and video files. Viruses also spread through downloads on the Internet. They can be hidden in illicit software or other files or programs you might download.

Amount of viruses detected by various anti-virus software last year:

vendor detected total percent
AntiVir 26,457,598 28,024,135 94.41%
Avast-Commercial 12,425,965 13,437,873 92.47%
Norman 25,264,055 27,467,379 91.98%
F-Prot6 17,295,119 19,004,580 91.01%
Sophos 3,345,699 3,691,679 90.63%
NOD32 25,329,840 28,024,135 90.39%
AVG7 25,262,433 28,024,135 90.15%
F-Secure 25,148,742 28,024,135 89.74%
Ikarus 9,275,581 10,476,608 88.54%
TrendMicro 11,703,755 13,437,873 87.10%
QuickHeal 10,190,639 11,846,198 86.02%
DrWeb 23,856,884 28,009,899 85.17%
VirusBuster 13,881,573 16,859,499 82.34%
Vexira 13,877,493 16,859,499 82.31%
Clam 12,232,194 15,305,470 79.92%
BitDefender 22,070,962 28,024,135 78.76%
Kaspersky 20,835,947 28,024,135 74.35%
McAfee 12,332,904 16,744,538 73.65%
VBA32 18,326,900 26,958,740 67.98%
Panda 7,661,487 12,300,516 62.29%
G-Data 1,186,992 3,679,871 32.26%


It is shocking to know that our computer system is exposed to these malicious threats. It is of the utmost importance to always have your anti-virus software updated because these threats can adapt to changes and evolve through time.

The following are some ways to keep these threat at bay:

  1. Always ensure that the Internet firewall is running. Firewalls are frequently used to prevent unauthorized Internet users from accessing private networks connected to the Internet, especially intranets. All messages entering or leaving the intranet pass through the firewall, which examines each message and blocks those that do not meet the specified security criteria.
  2. Subscribe to industry standard anti-virus software. In the case of a breach in security, these anti-virus software could trap the viruses and alert users of the breach and take the necessary steps to eliminate the viruses.
  3. Never open an e-mail attachment from someone you don't know.
  4. Avoid opening an e-mail attachment from someone you know, unless you know exactly what the attachment is. The sender may be unaware that it contains a virus.
Finally, as the saying goes - prevention is better than cure.

how to safeguard our personal and financial data?

Identity fraud and financial account fraud are not new. Criminals used to gain access to individual’s sensitive personal information with low-tech primary methods such as stealing their mail. But the methods used by criminals to gain access to the personal information that makes these crimes possible are changing with our times. Criminals are now turning to more technologically sophisticated methods of gathering and exploiting personal information.

Therefore, necessary steps to protect the security of individuals' information has to be taken seriously. A few of these safeguards will be discussed below.


Firstly, and also most traditionally, is to create strong passwords and PIN numbers to protect data from being assessed by using a combination of alphabets and numerics.


Besides that, it is crucially important to not only install but constantly update antispyware and antivirus programs. Popular programs include Norton AntiVirus and AVG Antivirus.

Other than that, installing a firewall is also another good safeguard as a firewall is a barrier to keep destructive forces away from your property. In fact, that's why its called a firewall. Its job is similar to a physical firewall that keeps a fire from spreading from one area to the next. Most computers today come with firewalls integrated into their operating systems.

Another safeguard would be to avoid assessing personal and financial information in public places such as cafes and restaurants. This can encourage hackers to hack into your confidential data and steal information from anywhere on the network.

The internet is a great source of information, but obviously also a great danger. However, if appropriate safeguards are taken, it is possible to protect personal and financial data.

Friday, January 30, 2009

How E-Commerce can reduce cycle time, improve employees' empowerment and facilitate customer support

Reduced Cycle Time


Cycle time is the amount of time a particular organization takes to complete any process. Such processes include, collecting accounts receivables, returning a quotation, and getting product out into the marketplace. The latter, is probably the most common in e-commerce. According to a report published by the FedEx Center for Cycle Time Research at the University of Memphis, "All too often in organizations, less than 3% of the elapsed time performing a process has anything to do with real work." The rest is spent on "scheduling, waiting, needless repetition, getting lost (and) getting found."

However, with the emergence of e-commerce and the advances in technology, cycle time could be reduced. For example, obtaining music, one needs to go to the music store to get a physical copy of the album before the emergence of e-commerce. Now with e-commerce, one only needs a computer system and Internet connection to obtain those music digitally. E-commerce reduced delivery time of digitized products and services to mere seconds. Furthermore, e-commerce could eliminate activities that are non-value added.

Activities such as documentation and administrative works could be reduced by more than 90%. Everything is made through computer systems. Employees need not search around for information and walk around the office to pass product orders. All is done via e-commerce.

---------------------------------------------

Improved Employee Empowerment


Employee empowerment is the extent of authority given to the employee to make decisions independently by the organization. This is enabled when the company adopts a decentralization decision making process. It gives the employees more freedom.

With e-commerce, almost everything is made available with a click of the mouse. Such as, customer history, product information, delivery mode, payment mode, promotion and discounts. Employees could make decision on the spot without consulting their superiors. This means that sales could be finalised and closed faster. Hence, making more sales.

--------------------------------------------------

Facilitate Customer Support


E-commerce enables the organization to provide value-added services and update to recurring customers and new customers alike. With the information in the organization's database, it could recommend the right products to the right customers.

For example:

I bought the items below from Amazon.com.

Shipment #1: Shipped on November 30, 2008 Need to return an item?
Shipping estimate:November 30, 2008
Delivery estimate:December 23, 2008 (More about estimates)
1 package via Expedited Int'l Shipping
Shipping Address:
Amy Loke
No. 2, Jalan 5/38C,
Taman Sri Kepong Baru
Kuala Lumpur, Kuala Lumpur 52100
Malaysia

Shipping Speed:
Expedited International Shipping

Items Ordered Price
1 of: Twilight: The Complete Illustrated Movie Companion [Paperback]
By: Mark Cotta Vaz
Sold by: Amazon.com, LLC
$10.19
- 1 item(s) Gift options: None

1 of: The Twilight Companion: The Unauthorized Guide to the Series [Paperback]
By: Lois H. Gresh
Sold by: Amazon.com, LLC
$10.36
- 1 item(s) Gift options: None



Item(s) Subtotal: $20.55
Shipping & Handling: $25.97

-----
Total Before Tax: $46.52
Sales tax: $0.00

-----
Total for this Shipment: $46.52

-----


A few weeks later, Amazon.com sent me an email recommending a product relevant to the goods that I've bought.

amazon.com
Let them choose from millions of items › Amazon.com Gift Cards
Your Amazon.com Today's Deals See All Departments
Dear Amazon.com Customer,

As someone who has purchased Stephenie Meyer books, "Twilight" music, or "Twilight" accessories, or searched for "Twilight" at Amazon.com, you might be interested in "Twilight" on DVD, available to pre-order only at Amazon.

Also, learn more about the film, buy movie merchandise, and watch our interview with Robert Pattinson at the "Twilight" Store: www.amazon.com/twilight.

Check out the DVD

With the help of e-commerce, the organization could lock customers in by giving them what they want and what they might want in the future by analyzing their buying habits.

An example of an E-Commerce failure and its causes


Pets.com was an online business that sold pet accessories and supploes direct to consumers over the Web. It was launched in August 1998 and went into liquidation within 9 months. It was also well-known for its wildly popular sock puppet spokesdog.

After its start by Greg McLemore, the site and domain was purchased in early 1999 by leading venture firm, Hummer Windblad, and executive Julie Wainwright. Amazon.com was involved in Pets.com's forst round of venture funding. Pets.com would eventually buy out one online competitor, Petstore.com in June.

The company rolled out a regional advertising campaign using a variety of media (TV, print, radio and eventually a Pets.com magazine). It started with a five-city advertising campaign rollout and then expanded the campaign to 10 cities by Christmas, 1999. The company succeeded wildly in making its mascot, the Pets.com sock puppet, well known. The puppet, performed by Michael Ian Black (alumnus of MTV's surrealist comedy sketch show, The State), was a simple sock puppet with button eyes, flailing arms, a stick microphone emblazoned with 'Pets.com", and a Timex watch around its neck.



Tthe Pets.com design was extremely well received, garnering several advertising awards. in January 2000, the company aired its first national commercial as a Super Bowl ad which cost the company $1.2 million and introduced the country to their answer as to why you should stop at an online pet store: "Because Pet's Can't Drive!" That as was ranked #1 by the USA Today's Ad Meter and had the highest recall of any ad that ran during the Super Bowl. The company went public in February 2000; the former Nasdaq stock symbol was IPET. It was the last dot-com to go public before the bubble burst.

Pets.com did make significant investments in infrastructure such as their warehousing; these investments resulted in the company needing critical mass of customers to break even. Pets.com's management maintained that the company needed to get to a revenue run rate that supported this infrastructure buildout. They believed that the revenue target was close to $300 million to hit the breakevem point and that it would take a minimum of 4 to 5 years to hit that run rate. This tim period was based on growth of the Internet shopping and the percentage of pet owners that shopped on the Internet.

By fall of 2000, and in light of the venture capital situation after the bursting og the dot-com bubble, the Pets.com management and board realized that they would not be able to raise further capital. They aggressively undertook actions to sell the company. PetSmart offered less than the net cash value of the company, and Pets.com's board turned down that offer. The company announced they were closing their doors on the afternoon of November 6, 2000, mere hours before the 2000 United State presidential election.

A few of the causes:
  1. Unsustainable business model and unachievable expectations. Basically, Pets.com bet everything on the market. It acquired ;arge amounts of funding from venture capitalists without demonstrating any background of achievements or success. Pets.com assumed that the market and its revenues would grow quickly enough before the funding money was used up. This e-tailer may have also overestimated the number of online customer it could gain in the pet market
  2. Pets.com went public too soon and spent money too quickly. It spent excessively on marketing and advertising. Pets.com advertised more heavily than any other online pet e-tailer. This excessive advertising did not only benefit Pets.com, rather it helped the entire online pet industry to increase sales. Hence, making its own competition.
  3. Pets.com failed to position itself in an effective manner. Pets.com jst offered prodcts that could be more easily obtained at a nearby mall and pet information about health, grooming. beahavior and such did not justify a virtual shopping trip. It also decided to compete with low prices just like its competitors that led to the selling of merchandise at prices below cost for the duration of its operations.