Saturday, June 21, 2008

The threat of online security: How safe is our data?

Nowadays, people rely on computers to create, store and manage critical information. Consequently, it is important for users to aware that computer security plays a major role in protecting their data from loss, damage, and misuse. Similarly, online security has been online trader’s main concern in protecting their websites from potential threats, such as phishing, security hacking, information theft, virus, worms and etc.

However, the increasingly developed technologies sarcastically increase the risk every computer user faced. Everyone who owns a computer with internet connection is able to equip themselves with ‘hacking’ knowledge by making some research online. Internet provides the opportunities for users to share the knowledge without filtering the content. Therefore, everyone can learn skills that may jeopardize online security via internet and therefore increase the online security risk.

Nowadays, computer users are facing the threats of cybercrime, phishing, internet and network attacks such as computer viruses, worms and Trojan horses and back doors.

Cybercrime is defined as online or internet-based illegal acts. Hackers, crackers and corporate spies who have advanced computer and network skills access computers and networks illegally with the intent of destroying data, stealing proprietary data and information.

Phishing is a scam in which a perpetrator sends an official looking e-mail that attempts to obtain your personal information and financial information. For example, some phishing e-mail messages ask you to reply with your information, or a pop up window that looks like a website, that collects the information. The damages caused by phishing can be crucial. The following case illustrates potential threat caused by phishing.

For example, in 21 June 2007, a spear phishing incident at the Office of the Secretary of Defense (OSD) stole sensitive U.S. defense information, leading to significant changes in identity and message-source verification at OSD. This incident has cost administrative disruptions and personal inconveniences, as well as huge financial loss in making system recovery.

Internet and network attack that jeopardize security include virus, worm, and Trojan horse. Virus is a piece of code that is secretly introduced into a system in order to corrupt it or destroy data. Virus attack can damage the operating system, causing the loss of data and other possible losses. A worm is a program that copies itself repeatedly. The repeatedly copied files use up the available space and slow down a computer operating speed. On the other hand, a Trojan horse is a program that hides within or looks like a legitimate program. Although they seem to be harmless, they may however be triggered if certain condition is certified.

A back door is a set of instructions in a program that allow users to bypass security control when accessing a program, computer, or network. Once perpetrators gain access to unsecure computers, they often install a back door or modify an existing program to include a back door, enabling them to continue to access the computers remotely without the user’s knowledge.

In conclusion, risk exposed by computer users is increasing with the increasing developed technology. Therefore, safeguards developed must be always up to date to enhance the defenses against online security threats. In the same time, users must be educated and informed about the crucial damages and loss caused by imposing online security threats.


References:
http://www.govexec.com/story_page.cfm?articleid=39456
http://en.wikipedia.org/wiki/Timeline_of_computer_security_hacker_history

Phishing: Examples and its prevention methods

Phishing is a criminal and fraudulently activity carried out on computers to acquire sensitive information such as try get hold of a person’s user name, password and credit card details. The most common way that phishers will attempt to get this information is by email or instant messaging and often directs users to enter details at a website. Normally, PayPal, eBay and online bank are phisher’s common targets. The damages cause by the phishing is that the victims may incur the financial loss due to denial access to the email.

There are some examples of the phishing:


The email looks like a real Citicorp email and the link in the email contains the name "Citibank". However, it has nothing to do with Citibank. To see the real link in an email message, right click on the text and choose “properties” from the context menu. To see an example of a faked link, try to log on to http://www.microsoft.com


This is an eBay phishing email includes the eBay logo in an attempt to gain credibility. The email notes that the billing information in the account is error and the eBay member need to login and verify the charges.

There are some methods use to prevent the phishing such as never reply to email that request your personal information or financial information. You should be suspicious when one sends you any email to ask you update your personal information or confirm it. Besides that, use anti virus and anti spam software and update them all regularly to ensure that you are blocking from new virus. The anti spam software can be use to analysis the content within the message or in urls and delete the phishing mail while the normal email gets filtered through to your inbox. Another way to prevent the phishing is review credit card and bank account statement regularly to ensure that no unauthorized transactions have been made. If your statement is late, call your credit card company or bank to confirm your billing address and account balances.

Friday, June 20, 2008

The application of 3rd party certification programme in Malaysia

What and why we need third-party certification?

Third-party certification is a scientific process by which a product, process or service is reviewed by a reputable and unbiased third party to verify that a set of criteria, claims or standards are being met. A third-party certification can reduce the time and expense needed for identifying, selecting and purchasing the products. Third-party certification is not the final word. The consumer has the final say. But a third-party certification claim is an important factor to consider when selecting a product.

The basic values of a third-party certification are to provide a measure of conformity, satisfy customer demands and limit supplier risks without the expense of repeating tests. Certifying organizations are anxious to maintain their reputation and sustain their integrity and will provide an excellent way to validate trustworthy of website while protecting consumers from myths, misconceptions, misleading information and “fly by night” manufacturers.

Example:


MSC Trustgate.com Sdn Bhd is one of the popular Certification Authority (CA) in Malaysia and it is recognized by most of the Malaysian as a mark of safety and quality. MSC Trustgate has joint venture with the Verisign which is the largest certificate authority behind the encryption and authentication on the Internet in American. Verisign provide the SSL (Secure Sockets Layer) technology to MSC Trustgate, this is a cryptographic protocols that provide secure communications on the Internet for such things as web browsing, e-mail, Internet faxing, instant messaging and other data transfers. Maybank2u is using the MSC Trustgate SSL to enables encryption of sensitive information during online transactions.

Wednesday, June 18, 2008

How to safeguard our personal and financial data?

As technology in this world improved day by day, our personal and financial information are getting easily and easily to be stolen and misused. People can access our personal data as well as our financial data easily trough internet. Other than that, they may also get the data by steal our wallets and purses that contains our identification; steal our mail, for example, bank and credit card statements; steal files or bribe employees who have access to files with our information and many more. Most of people that been stolen their personal and financial data will suffer financial loss. For example, the thief might use our bank account or credit cards. So, we need to take some important steps to prevent and also to safeguard our personal and financial information.

First of all, we should increase our awareness of how and when we use our personal information. By doing this, we can reduce the chance that our personal information from being misuse. This can be done by follow some steps suggested below.

Firstly, never give personal or financial information over the phone or Internet unless you initiated the contact. If you are told to send your information through email or phone, do not entertain it. It can be easily stolen.

Secondly, use strong password and try to avoid using your date of birth as password.
Most importantly, memorize the password. Do not record the password on paper that carry with you.

Thirdly, check your monthly credit card and bank statements for unusual activity. If you found any unusual record in your statement, contact the relevant authorities to check out with it.

Fourthly, use a firewall program on your computer, especially if you leave your computer connected to the Internet 24 hours a day, and never download files that sent by strangers. It helps to prevent hacker and cracker to obtain our information.

Lastly, shred receipts and copies of documents with personal information if they are no longer needed. Some identity thief might rummage through your trash to get your personal data. So, if we shred it, they would never had chance to look at it.

Other than preventing, if we suspect that we had become a victim of personal and financial data thieves, we should act immediately. We should recall all the activities that might cause the data stolen and try to remember the person that we suspected. Then, we should call the police and immediately close the account that had been theft.

As a conclusion, prevention is better than cure. We should always alert and aware of the confidentiality of our personal and financial data. We can stop it before it happen.

Saturday, June 14, 2008

E-Commerce reduces cycle time, improves employee's empowerment and facilitates customer support

E-commerce is short for electronic commerce, which is defined as the marketing of goods and services over the internet. Most of the large businesses typically have e-commerce websites, enabling customers and sellers to conduct business online. The websites established usually show details of their products and services, as well as related company information. Customers, sellers and interested parties can access to this information online.

Cycle time is defined as the amount of time the company takes to complete a business process. It is also defined as the time that elapses from the beginning to the end of a process. E-commerce reduces cycle time. It shortens the buying process. E-commerce does not only provide tangible products, but it includes a variety of products and services. E-commerce nowadays provides products and services like retail, finance, entertainment and media, and travel etc. With just few clicks, customers are able to find the stuff they desired. And these purchases can be done in few minutes online. E-commerce decreases and even eliminates the frustrations of locating and waiting for the product customers want by searching from mall to mall. The most well known e-commerce company is Dell Computers. Dell uses the Internet to enhance the advantages of direct marketing and hosts one of the world’s largest volume e-commerce Web sites. Customers can configure and price computers, order systems, and track their orders online. Its websites also provides simple interface for smooth transactions. Therefore, customers can purchase the desired Dell computers in beneficial and comfortable ways. This simple interface increases the sales and customer satisfactions in the same time.

Employee empowerment is the practice of giving non-managerial employees the obligations and the power to make decisions regarding their jobs or tasks. Large businesses nowadays need e-commerce to diversify their services. They do not only provide their products and services in shops, they provide such services online as well. With the establishment of e-commerce, employees can be empowered by delegating e-commerce responsibilities to them, such as allowing their employee to design the web sites and process, control and ensure the smoothness of transactions online, respond to complaints and suggestions of customer online, as well as updating company web site’s information, such as products details and news.

E-commerce websites are always equipped with Frequently Asked Questions (FAQ) section to facilitate customer support. This section contains frequently asked questions, together with the answers. Therefore, whenever customers have any doubts on the products or services provided in e-commerce website, they can first check at FAQ section. Alternatively, if the mentioned section still does not answer customers’ doubts and questions, they can write complaints via e-mail and e-mail them to the e-mail address provided. The contact details are usually listed in ‘customer service’ section provided in e-commerce website. For example, Dell e-commerce website is equipped with ‘customer service’ under ‘support section. Therefore, if the customers have further questions, they can contact Dell via e-mail or phone call, as provided in Dell’s website.

As a result, e-commerce nowadays has been improved continuously and it starts to gain confidence of consumers increasingly. Therefore, e-commerce has a promising future and it can be a great success if it is used and implemented in a smart way.

The Failure of Webvan.com and Its Causes

Webvan.com was an online grocery business that delivered products to customers’ homes within 30-minutes after their choosing. It was started in early of year 1999 and offered its services in 9 different cities in United State. Within a short period, the company grew very fast and it attracted many funding and managed to raise its capital to $375 million USD in an IPO (Initial Public Offering). This raise gave Webvan.com confidence to continue expand its business to other 26 cities in a short period. However, in early of year 2001, Webvan.com started to close down its business over the country and the CEO, George Shaheen, had stepped down. In a few months time, Webvan.com had run out of money and its stock price had dropped from $30 USD to $0.06 USD. In July 2001, the company’s shareholders voted to approve a 25-to-1 reverse stock split in a last ditch effort to keep the company afloat. Unfortunately, it was too late. A week later, Webvan.com shut down its operations.

The failure of Webvan.com had a few causes. Although the Webvan.com spokesman Bud Grebey said that the shut down of Webvan.com is caused by the company changed its delivery fees, bad press over former CEO George Shaheen stepping down and a critical auditor's report, but it isn’t so. One main factor that causes Webvan.com to shut down was the company grew too big in too short period. The company focus on short-term profit rather than long-term. Webvan.com had ignored the growth and market share which were important component to success in long-term. Other than that, it was too soon for the company to grow and expend to 26 cities coverage market within a two to three year time. It had not attracted enough customers to justify its spending.

Other than that, the second factor that leads to Webvan.com’s failure was too much spending in infrastructure. Webvan.com spend too much than its earning. For example, it signed a $1 billion USD contract to build a string of high-tech warehouses worth about $30 million each. It is way too much for the company’s income. The investment is greater than its sales growth. The plan of expanding in short period also had made a big impact in losing their income quickly.

The third reason of Webvan.com failure is that the company did not attempt a partner which is a brick-and-mortar organization. The company did all things by themselves. But technically, the company did not have any experience or knowledge in supermarket industry. It developed its own infrastructure to deliver groceries. The company should have partnered with an existing supermarket chain or wholesalers for example.

As a conclusion, although Webvan.com was very successful for attracting investors, but it failed to attract partners to help them. These reasons had lead to the failure of this company in a short period.


References:

  1. Farmer, M.A., & Sandoval, Greg (2001). Webvan delivers its last word: Bankruptcy. Retrieved June 12, 2008, from http://news.cnet.com/Webvan-delivers-its-last-word-Bankruptcy/2100-1017_3-269594.html?tag=news.1

  2. German, Kent (n.d.). Top 10 dot-com flops. Retrieved June 12, 2008, from http://www.cnet.com/4520-11136_1-6278387-1.html

Thursday, June 12, 2008

History and Evolution of E-Commerce

E-Commerce was birth out from the World-Wide-Web (WWW). The first extended use of a form of electronic commerce appeared in the early 1970s, when system called Electronic Fund Transfer (EFT) was introduced. This enabled banks and financial institutions to transfer over secure networks large amounts of money either among themselves or with associated businesses.

In the late of 1970s, the introduction of the Electronic Data Interchange (EDI) made it possible for companies to interface and trade without any human contact and it enables inter-company exchanges of documents, such as order forms for suppliers, invoices, customs forms, reimbursement receipts, stock inventories and etc.

In the late 1980s, the new type of applications which is electronic mail (e-mail) was widely adopted in the business world. When it was first introduced, this system was considered a major breakthrough.

In year 1992, The National Science Foundation lifted restrictions on the Internet allowing commercial use. CompuServe offers online retail products to its customers. This gives people the first chance to buy things off their computer.

In year 1994, Netscape arrived which providing users a simple browser to surf the Internet and a safe online transaction technology called Secure Sockets Layer.

In year 1995, two of the biggest names in e-commerce are launched which is EBay and Amazon.com. Generally, B2C websites are the bridge that link customers to suppliers such as EBay, online auction. Beside that, the B2C concerns itself with selling to the end user such as Amazon, online book retailers. On the other hand, the e-commerce that is conducted between businesses is referred to as B2B such as Microsoft sell his software to other organization.

In the very beginning, many people will have doubt on e-commerce but now it is become a modern tool, not only e-commerce revolutionized the world of wholesale, but also retail. As a result of that, the businesses are now continually searching for new ways to meet the needs of the online market such as Wal-Mart, they target on integrating consumer relationship with e-commerce industry to increases their customer base.

The technology used for e-commerce is young, but it's expanding faster than any before it and will soon be the most advanced system the world has ever seen and e-commerce is still one of the leading forces of economic growth today.