05 July 2008
What is Phishing?
Phishing is a new type of network attack where the attacker creates an imitation of an existing Web page to trick users into submitting personal, financial, or password data to what they think is their service provides’ Website. The frequently used attack method is to send e-mails to potential victims, which seemed to be sent by banks or online organizations. In these e-mails, they will make up some causes, e.g. the password of your credit card had been mis-entered for many times, or they are providing upgrading services, to attract you visit their Web site to conform or modify your account number and password through the hyper link provided in the e-mail. You will then be linked to a fake website after clicking those links. The style, the functions performed, sometimes even the URL of these faked Websites is similar to the real Website. It’s very difficult for you to know that you are actually visiting a malicious site. If you input the account number and password, the attackers then successfully collect the information at the server side, and is able to perform their next step actions with that information like withdraw money out from your account.
How to Prevent Yourself from Phishing?
The best way you can prevent yourself from phony phishers is to understand what legitimate financial service are providers. Most importantly, legitimate entities will not ask you to provide or verify sensitive information through an email.
Follow these five simple steps to prevent yourself from phishers:
- Pick up the phone to verify — do not respond to any emails that request personal or financial information, especially ones that use pressure tactics or prey on fear. If you have reason to believe that a financial institution actually does need personal information from you, pick up the phone and call the company yourself using the number in your rolodex, not the one the email provides!
- Do Your Own Typing — Rather than merely clicking on the link provided in the email, type the URL into your web browser yourself or uses a bookmark you previously created. Even though a URL in an email may look like the real deal, fraudsters can mask the true destination.
- Beef up your security — Personal firewalls and security software packages with anti-virus and anti-spam are a must have for those who engage in online financial transactions. Make sure your computer has the latest security patches, and make sure that you conduct your financial transactions only on a secure web page using encryption. You can tell if a page is secure in a couple of ways. Look for a closed padlock in the status bar, and see that the URL starts with “https” instead of just “http”.
- Security Tip: Some phishers make spoofed websites which appear to have padlocks. To double check, click on the padlock icon on the status bar to see the security certificate for the site. Following the “Issued to” in the pop-up window you should see the name matching the site you think you’re on. If the name differs, you are probably on a spoofed site.
- Read your statements — don’t toss aside your monthly account statements! Read them thoroughly as soon as they arrive to make sure that all transactions shown are ones that you actually made, and check to see whether all of the transactions that you thought you made appear as well. Be sure that the company has current contact information for you, including your mailing address and email address.
- Spot the sharks — Visit the Website of the Anti-Phishing Working Group at www.antiphishing.org for a list of current phishing attacks and the latest news in the fight to prevent phishing. There you’ll find more information about phishing and links to helpful resources.
02 July 2008
The causes of credit card debt are poor money management, saving too little or not at all, financial illiteracy. The poor money management is a monthly spending plan is essential. Without one you have no idea where your money is going. You may be spending hundreds of dollars unnecessarily each month and end up having to charge purchases on which you should have spent that money. The saving too little or not at all is means it is not to prepare for unexpected expenditures by saving three to six months of living expenses. The financial illiteracy is many people don't understand how money works and grows, how to save and invest correctly, or even why they should balance their checkbook.
The preventions are planning is no more difficult than writing down your expenses and income and reconciling the two. You will be surprised at how powerful you'll feel when you are making thoughtful decisions about where and when to spend your money. It is to avoid unwanted debt, the saving is important and if anything happen, it will not cause immediate financial strain and increase debt. It is better learn to get educated and get in control at the money.
01 July 2008
• The threat of online security: How safe is our data?
0 comments Posted by Creative E-com at 5:00 PMCurrent software allows one to transfer data from networked computer to outside computer, thus providing flexibility especially to the corporate field. However, the same software creates breeches to the security. One of the most common crimes in the era of technology is identity theft. It is also a fast growing and a serious crime that has penetrated in the recent era.
Identity theft happens both online and offline. One of the ways that identity thieves collect personal and financial information about members of the public offline is to filter through carelessly discarded trash. Many people throw bank statements, utility bills and other potentially sensitive documentation away without shredding it first. An identity thief can find enough about someone - just from their dustbin or mailbox - to steal their identity. Identity thieves steal personal and financial information online more purposely, with phishing attempts for example but it is often because of carelessness or complacency, regarding personal and financial information.
Once an identity thief has obtained someone's personal or financial information identity thieves will steal your money from your accounts and savings, run up enormous credit card bills, and obtain passports and other official documents, empty bank accounts - even using their ill-gotten gains to fund other crimes, such as drug running and terrorism. The legitimate owners of the information identity thieves’ abuse can spend vast amounts of time and money trying to undo the damage to their finances and their reputations. This often raises the question of how safety is our personal data online. There are many ways of obtaining ones personal data. For example:
1) Email-Transaction Identification
2) Web-Transaction Identification
3) Location Extraction
4) Routinised Self-Identification
5) Dataveillance
The road to recovery after the identity has been stolen is a long one but it is not impossible to repair the damage. Because identity theft is such a high profile crime, it is easy to get help and support whilst one check their details and put measures in place to contain the threat. However, there are several ways to repair the damage as quickly as possible. Firstly, call law enforcement and report the identity theft. Make sure you get an incident number. Secondly, report all lost or stolen documents, such as passports, driving licenses, credit cards, chequebooks. Thirdly, notify your bank, credit card company and any other financial institution that holds you details. Tell them directly that you are contacting them about identity theft. You will need to close any accounts that have been compromised, which will be inconvenient but will prevent an identity thief from stealing any more of your money (assuming they have not already emptied your accounts).
Cancel your checkbooks, credit and ATM cards and get anew PIN[s] besides notifying the postal service[s] if you think that your mail has been tampered with or redirected. Then, contact any companies where accounts have been opened in your name and tell them that you are a victim of identity theft. They will have a policy in place to deal with your inquiry. Finally, contact the main credit bureau, tell them that you have been a victim of identity theft, and ask them to monitor your credit activity. Ask them to send you a credit report that, when you receive it, study very carefully for discrepancies.
There are several steps to minimize the risk of ones identity being stolen. However, no matter how careful or what steps been taken to safeguard the information, it is a sad fact that as with all crime despite the best efforts, it can only minimize the risk. Being cautious is not the same as being invincible.
25 June 2008
The application of 3rd party certification programme in Malaysia
0 comments Posted by Creative E-com at 8:17 PMBesides, VeriSign Secure Site is use to ensure data confidentiality and integrity, all information transmitted over the Internet is encrypted using the 128-bit Secure Sockets Layer (SSL) protocol from Verisign Certificate Authority. SSL is a secure way of transferring information between two computers on the Internet using encryption. Strong end to end encryption is also adopted within the bank’s computer networks and resources. SSL helps you deliver a secure and convenient way for your customers to interact with you over the Internet. When you display the VeriSign Secured Seal, your customers will recognize the most trusted security mark on the Internet and gain the confidence to complete their transactions with you.
Lastly, by applying 3rd party certification, there are more safeguard for online shopping, which means the customers can shop safely. In addition, the confidentiality of customers towards the internet will also be enhanced and hence the organizations will be able to earn more profits.
24 June 2008
Here are a few approaches on how to safeguard our personal and financial data:
· Avoid using passwords that are easy for someone to guess, such as the name of your favorite pet or your date of birth. Never write this information down and never carry it in your wallet or briefcase.
· Regularly scan your computer for spyware - Spy ware or adware hidden in software programs may affect the performance of your computer and give attackers access to your data. Use a legitimate anti-spyware program to scan your computer and remove any of these files
· Do not reveal any personal information or particularly passwords to anyone. After using any of the Financial Data Center or member services, must remember to log out properly before leaving the Financial Data Center.
· Establish guidelines for computer use - If there are multiple people using your computer, especially children, make sure they understand how to use the computer and Internet safely. Setting boundaries and guidelines will help to protect your data
· Follow corporate policies for handling and storing work-related information - If you use your computer for work-related purposes, make sure to follow any corporate policies for handling and storing the information. These policies were likely established to protect proprietary information and customer data, as well as to protect you and the company from liability.
· Avoid unused software programs - Do not clutter your computer with unnecessary software programs. If you have programs on your computer that you do not use, consider uninstalling them.
· Pay attention when using an ATM and keep your eyes peeled for anyone who seems a little too interested in your transactions. Use your free hand to shield the keypad when entering your PIN. Besides that, banker can add on fingerprint scanning on ATM machine.
· Keep software up to date - Install software patches so that attackers cannot take advantage of known problems or vulnerabilities
· Use and maintain anti-virus software and a firewall - Protect yourself against viruses and Trojan horses that may steal or modify the data on your own computer and leave you vulnerable by using anti-virus software and a firewall. Make sure to keep your virus definitions up to date.
· Follow good security habits - Review other security tips for ways to protect yourself and your data.
· Keep your card close. Whether you are out shopping or eating out, watch how clerks handle your card. Then take your receipt with you and never throw it away in a public place.
· If share information with another user or use our services on a public computer such as in a public library, school computer lab or Internet cafe, must remember to close the browser window. That is to prevent other users from reading your personal information and mail.
19 June 2008
Millions of collectible, decor, appliances, computers, furniture, equipment, vehicles, and other miscellaneous items are listed, bought, and sold daily. In 2005, eBay launched its Business & Industrial category, breaking into the industrial surplus business. Some items are rare and valuable, while many others are dusty gizmos that would have been discarded if not for the thousands of eager bidders worldwide. Anything can be sold as long as it is not illegal and does not violate the eBay Prohibited and Restricted Items policy. In June 2006, eBay added an eBay Community Wiki and eBay Blogs to its Community Content which also includes the Discussion Boards, Groups, Answer Center, Chat Rooms, and Reviews & Guides.
EBay has a robust mobile offering, including SMS alerts, a WAP site, and J2ME clients, available in certain markets Best of eBay is a new specialty site for finding the most-unusual items on the eBay site. In 2007, the total value of sold items on eBay's trading platforms was nearly $60 billion. This means that eBay users worldwide trade more than $1,900 worth of goods on the site every second. eBay offers various online help features, including a library of self-help resources, e-mail contact forms and "Live Help," which lets users chat with customer service representatives via instant messaging. Although this is not available to users on international sites such as eBay.co.uk, members of international eBay Web sites are welcome to utilize eBay.com's Live Help service. eBay does offer some phone support to its customers although this is limited to sellers of the rank "Bronze PowerSeller" and above, the company's term for members who sell at least an average of $1,000 worth of goods per month on the site, as well as to eBay Store owners. PayPal is an e-commerce business allowing payments and money transfers to be made through the Internet. It is also a European bank based in Luxembourg. It serves as an electronic alternative to traditional paper methods such as cheques and money orders. PayPal performs payment processing for online vendors, auction sites, and other corporate users, for which it charges a fee. It sometimes also charges a transaction fee for receiving money (a percentage of the amount sent plus an additional fixed amount). The fees charged depend on the currency used, the payment option used, the country of the sender, the country of the recipient, the amount sent and the recipient's account type. On October 3, 2002, PayPal became a wholly owned subsidiary of eBay PayPal enables any individual or business with an email address to securely, easily and quickly send and receive payments online. It has 149 million registered users and is accepted by millions of merchants worldwide - on and off eBay. PayPal's Q1 2008 global total payment volume of $14.4 billion accounted for nearly 9 percent of worldwide eCommerce. Acquired by eBay Inc. in October 2005, Skype is the world's fastest-growing Internet communication company that has revolutionized the way people talk online. With more than 309 million registered users as of early 2008. In addition to its presence on eBay, Skype has relationships with a growing network of hardware and software providers. Other key acquisitions have strengthened eBay Inc.'s portfolio of ecommerce companies, Stubhub, a leading online marketplace for the resale of event tickets; rent.com, the most visited online apartment listing service in the U.S.; StumbleUpon, an online solution that helps people discover and share content on the web; and market-leading online classifieds sites including LoQUo.com, Intoko, and Netherlands-based Marktplaats.nl.



