Review on post Organisations Not Doing Enough to Secure Data
0 comments Posted by LAI SEM MIN at 12:56 PMApparently, organizations really not doing enough to secure the data in their computer. I had read an article about the hard and soft of deleting data, it show that the organizations do enough of caution to secure data from public, well not for smart thieves.
The United State environmental Protection Agency (EPA) reported that between 26 and 37 million computers came to the end of their life cycles in 2005. When the computer is improperly thrown out, it not only will endanger the environment, it will cause theft of data inside too. Even if the organization will delete the files inside and even format the hard drive, apparently this is not enough to secure the data.
Why deleting the files is not enough?
This is how a hard drive work. When you hit the delete key for a file, the operation system will flags the file as no longer needed and let the file handler know that this space is now available to be used for new data. The old data that is still stored across the surface of the disk and not actually removed or written over until another orogram come along and needs to store something, then the opreating system looks dor available spaces and releases to be used in small sections called blocks. Only when all the old blocks of data are written over will all the old data be gone.

Software to undelete files
Just google "undelete", and you will find that there are actually a few software to undelete file. Some of them are even free like FreeUndelete. This software are used to recover lost files as well as to find out what people had been doing to recover deleted files drom discarded computer.
How to secure yourself from data thieves?
You can reformatting the hard drives, but it will only make it harder for them to recover the files from the computer. There are actually some sophisticate way like data wiping software that overwrite hard drives with random binary numbers. Well, the easiest way is took out the hard drive from the computer and smash it into pieces. You may find some pleasure in it too.
It is important to secure your data to avoid the theft of important information. Leak of information of your company may harm your company. Ciao!!! See you in the next post..
Labels: Week 4
The Application of Third Party Certification Programme in Malaysia
0 comments Posted by Anonymous at 2:06 PMAs a result, there is a security practice on e-commerce websites called certification programme. It is also called “third party certification programme” because it is performed by a third party. It is also called Certificate Authorities (CA), who issues the digital certificate to verify and authenticate the website. Digital certificate can be considered as an electronic certificate that proves the credentials of a website when a company conducts business transactions on the Web. Usually it contains the holder’s name, validity period, public key information and a signed hash of the certificate data. It usually attach to an e-mail message or an embedded program in a web page. There are two main certificate authorities involve in third party certification programme in Malaysia, which are MSC Trustgate and VeriSign.
MSC Trustgate
MSC Trustgate.com Sdn Bhd is a licensed Certification Authority (CA) operating within the Multimedia Super Corridor. It was incorporated in 1999 to meet the aim of secure open network communications and encourage the growth of e-commerce both in Malaysia and across the ASEAN region. It is licensed under the Digital Signature Act 1997 (DSA), a Malaysia law that sets a global precedent for the mandate of a CA. Thus, its core business is to provide digital certification services, including digital certificates, cryptographic products, and software development. The vision of Trustgate is to enable organizations to conduct their business securely over the Internet, as much as what they have been enjoying in the physical world.
Trustgate is a subsidiary of Multimedia Development Corporation, which aims to promote the growth of e-commerce by creating a trusted e-environment that helps businesses to expand in the new economy. Trustgate is an affiliate of VeriSign in the South East Asia region as well as a member of VeriSign Trust Network. This affiliation affords the e-commerce company’s customers to enjoy a global wide recognized service that is aligned with the existing technological requirements. 
There are many types of products and services offered by Trustgate for example Secure Socket Layer (SSL) Certificate, Managed Public Key Infrastructure (MPKI), Personal ID, MyTRUST, MyKAD ID, SSL Virtual Private Network (SSL VPN), Managed Security Services, VeriSign Certified Training and Application Development. Below are some brief explanations of the products:
(1) SSL Certificate for Internet, Intranet and Server Security
~ SSL Certificate is an electronic file that uniquely identifies individuals and Web sites and enables encrypted communications. It secures communication between a server and a browser for internet, intranet and server security.
(2) Managed Public Key Infrastructure (MPKI)
~ MPKI is a fully integrated enterprise platform designed to secure intranet, extranet, and Internet applications by combining optimum flexibility, performance, and scalability with high availability and security. It enables rapid and effective establishment of a robust PKI and Certification Authority (CA) system with complete control over security policies, PKI hierarchies, authentication models, and certificate lifecycle management. The diagram below is flowchart of MPKI:
(3) Personal ID
~ It also known as Digital ID for securing transactions, documents and e-mails. Digital ID is an electronic credentials that uses private key and public key to facilitate authentication, privacy, and integrity purposes. Digital ID from MSC Trustgate.com is governed by the Digital Signature Act 1997. Without a legitimate Digital ID in electronic transaction, a contract is not admissible in court in the case of dispute.
(4) MyTRUST
~ By using MyTRUST, users can transform a SIM card into a Mobile Digital Identity for secure mobile banking and other financial services. Mobile digital signature provides non-repudiation on transactions under the Digital Signature Act, 1997. The users can be able to digitally sign any transaction easily via their mobile phone.
(5) MyKAD ID
~ MyKad (Malaysian National Identity Card) with PKI capability permits its holder to make online transaction with government agencies and private sectors like used in online tax filing, e-procurements and many more. MyKey, is the MyKad PKI solution that works with MyKad, allowing users to authenticate themselves online and to digitally sign documents or transactions and is accepted by the Malaysian government.
Trustgate ID Center
MSC Trustgate provides trusted and encryption technology that secure and protect online communication. As a result it may protect important business information from non-authorized access. It offers 128-bit SSL Server ID that is nowaday used in financial institutions, insurance companies, e-government, healthcare organizations and so on. Secure Server ID, Global Server ID, Trial SSL Server ID, MyKey are some of the security ID technology available in MSC Trustgate. Please click here for further information.
What are the functions of MSC Trustgate as Third Party Certification?
The main function of the existence of third party certification programme is to improve customers' trust when dealing business online since the threats of internet security become more crucial nowadays. The stolen of personal information such as Identification Number, credit card number, passwords and etc has worried the customers in dealing e-commerce transactions. Customers want to ensure that they are dealing with the trusted party, the third party certification is needed to ensure the information that they provided over the Internet is able to reache at the right recipients safely.
MSC trustgate can provide e-mail protection and validation, secure online shopping carts, payment security system and etc. in order to prevent the users'email are being spammed, hacked and attacked by the malicious software.
An e-commerce website with the certification from MSC Trustgate in Malaysia will enhance the confidence of customers by implementing more safeguard on online shopping. Customers can purchase freely without worrying their privacy and confidentiality of personal information are being threathened.
Verisign Secure Site is another third party certification programme that is internationally recognised. It is the most trusted symbol on the Internet, the seal of verisign is an instant evidence that a web site is genuine because it has been verified by the Certification Authority, thus the customers can conduct business without much worries. It offers security solutions to protect an organization's consumers, brand, website and network.
Verisign offers the strongest SSL encryption, and it is leading in Secure Sockets Layer (SSL) Certificate Authority. SSL is a protocol originally developed by Netscape in 1996 as a way of ensuring the security of e-commerce transactions, communications, and interactions for Web sites, intranets, and extranets. It transfers all the information through Internet using the 128-bit SSL protocol to encripted data. This is a secure way of transmitting information between two computers on the Internet using encyption. A powerful end-to-end encyption is also adopted within the bank's computer networks and resources. It aids all companies and consumers around the world to join in trusted communications and commerce.
In conclusion, Malaysia needs a well-mandated security infrastructure on e-commerce websites in order to protect the rights of users as well as the e-commerce publishers. The establishment of Certificate Authorities in Malaysia is very important and they play vutal role not only to catalysts the growth of e-commerce but also to inspect the security of e-commerce websites. We as the internet users must also be aware of some security trademarks, so that we would not become the victims of security issues. Please visit the links below for additional information:
Labels: Week 4
Phishers use a number of different social engineering and e-mail spoofing ploys to try to trick their victims. It normally started off with a link that will direct you to a fake website that look like a real one. Then, they will ask you to enter your details and BOOM, you had been phished.
Here is the definition from Webopedia:
phishing(fish´ing) (n.) The act of sending an e-mail to a user falsely claiming to be an established legitimate enterprise in an attempt to scam the user into surrendering private information that will be used for identity theft. The e-mail directs the user to visit a Web site where they are asked to update personal information, such as passwords and credit card, social security, and bank account numbers, that the legitimate organization already has. The Web site, however, is bogus and set up only to steal the user’s information.
- Generic greetings, like "Dear Customer." If your bank sends you an official correspondence, it should have your full name on it. (Some phishers have moved on to spear phishing, which can include personalized information.)
- Threats to your account and requests for immediate action, such as "Please reply within five business days or we will cancel your account." Most companies want you as a customer and are not likely to be so quick to lose your business.
- Requests for personal information. Most businesses didn't ask for personal information by phone or through e-mail even before phishing became a widespread practice.
- Suspicious links. Links that are longer than normal, contain the @ symbol or are misspelled could be signs of phishing. It's safer to type the business's URL into your browser than to click on any link sent in e-mail.
- Misspellings and poor grammar.
How to defence against phishing:
- Desktop protection agents -To protect against phishing, you have to have a good antivirus software that perform the following function:
• Local Anti-Virus protection
• Personal Firewall
• Personal IDS
• Personal Anti-Spam
• Spyware Detection - Browser capabilities - To help preventing phising attack,web browser user should
• Disable all window pop-up functionality
• Disable Java runtime support
• Disable ActiveX support
• Disable all multimedia and auto-play/auto-execute extensions
• Prevent the storage of non-secure cookies
• Ensure that any downloads cannot be automatically run from the browser, and must
instead be downloaded into a directory for anti-virus inspection - Detecting and blocking - It will be easier for you to detect a phishing scam manually rather than rely on a software. You can follow the instruction above to spot one. The thing is never ever entering any of your detail to the link that you have doubt on it. Be suspicious and that will save you from being phished.
Labels: Week 4
Do you ever think that how safe is it to perform a financial transaction thro
ugh online or even posting your personal details online? Nowadays people often create, store and manage critical information through computer. All kinds of activity from banking to storing company's personal details are done through internet. According to the 2009 Security Threat Report from Sophos, one new infected Web page is discovered every 4.5 seconds.
In today's world as technology are rapidly growing, performing activities as stated above are no longer safe. Now you have to worry about all the security problems when you are on the internet in a whole new different way. Spyware, adware, viruses and trojans are lurking online, waiting to infect your computer.
One of the most popular threat which will increases our risk when getting online is Spyware. Spyware are the most common online security threat faced by Internet users. Spyware is simply a computer program that is designed to steal information from your computer without your knowledge. The software will typically be installed on your computer without you even knowing it, and then it will send your personal information such as documents, passwords, credit card numbers, bank accounts, and many others to another source. Common spyware includes Trojan horses, key loggers, dialers, and adware programs.
Virus may als
o will form a threat to us when we are online-ing. Virus usually spread into our computer when we had click on certain unfamiliar websites or emails. A virus is a self-replicating/self-reproducing program that spreads by inserting copies of itself into other executable code or documents. Viruses are one of several types of malicious software or malware. A basic rule is that computer viruses cannot directly damage hardware, but only software. Often, when a virus infects your computer it can wipe out data, significantly affect computer operation, and use your Internet connection to spread.
Threats may also occur when surfing some social networking sites. Among the popular ones are such as Facebook, Myspace, Friendster. With social networking on the rise, the bad guys have found yet another playground on the Web. The Sophos report reveals 1800 Facebook users had their profiles defaced in August by an attack that installed a Trojan while displaying an animated graphic of a court jester.These sites has become a form of "launching pad" for mass distributing malware attacks and spam, like the recent Koobface Trojan which attacked both MySpace and Facebook and transformed victim machines into zombie computers to form botnets.
The followings are some of the security tips to prevent unwanted incident to happen.
• Don't give away any valuable or sensitive personal information on your MySpace or Facebook profile, or within messages to other members of the network. And don't click on any links in social network messages from people you don't know.
• No reputable company will ask for your password, account number, or other log-in information via e-mail or instant message.
• Use one of the many antivirus, antispyware, and firewall programs on the market. And many Internet service providers offer them free with your monthly subscription.
• Upgrade your web browser to the most current version.
• Pay attention to the messages from Windows that pop up on your screen. They often contain helpful security information that many users overlook.
• Turn on Windows' automatic-update function to get Microsoft's regular security patches.
The following are some references for you to know more about threats of online securities. Feel free to click on each of the links!!!
http://www.businessweek.com/technology/content/nov2007/tc2007119_234494.htm
http://techcruser.blogspot.com/2007/05/online-security-threats-to-your-pc.html
http://www.wisegeek.com/what-are-the-primary-online-security-threats.htm
http://www.tech-faq.com/online-security-threats.shtml
http://www.readwriteweb.com/archives/top_online_security_threats_for_2009.php
http://www.buysafe.com/security_center/security_glossary.html
http://www.infosectoday.com/Articles/Security_Threat_2009.htm
http://en.wikipedia.org/wiki/Spyware
Remember to secure your important data properly to prevent and unwanted incident happen!!!
Labels: Week 4

Nowadays, computer and Internet data storage are so common. Whatever we do in our life: banking, online paying, e-mailing, application, personal details, etc... All the data and information had been stored and managed in the computer. But, on the other hand, "data theives" are also become very common in this high-technology century. This group of people takes the advantage of our personal and financial data to make their own benefits. Therefore, we must have a set of effective methods to safeguard our data and information.
Here are some of the tips on how to safeguard our financial and personal data:
1. Passwords: 
Password is a code which consists of numbers or/and letters that is used for authentication or gain access to a resource. The password must be kept secret from those not allowed to access. Choose a strong password or difficult for someone who knows you to guess. Never choose your birth dates, phone number or names that can be easily guess by others. A combination of uppercase and lowercase letters, numbers are more encouraged. Change your password occasionally so that it will not easy to be traced by others.
2. Encryptions:
Encryption is encoding information to make the readable data to unreadable to anyone except the author and relevant party with the key to decode it. The word encryption also implicitly refers to the reverse process, decryption which means to make the encrypted information readable again. The purpose of encryption is to secure the data. This encryption involves mathematically-based scrambling of the data in files so that it is unreadable except by authorized users.
3. Firewall:
A firewall within a network is similar to physical firewalls with fire doors in building construction. A firewall is an integrated collection of security measures designed to prevent unauthorized Internet users from accessing private networks connected to the Internet. Firewall will keep the good people in and keep the bad people out. All messages entering or leaving the Internet pass through the firewall and firewall will examine each message and blocks those do not meet the specified security criteria.
4. Anti-virus software:
Install anti-virus software in computer to protect data against various viruses and Trojan
horses. Norton anti-virus is the most common software nowadays. Also, always make sure that the anti-virus software is up to date. The attackers will take the advantage of the outdated anti-virus software. Normally this kind of software offers automatic updates.
4. Scan computer for spyware:
Spyware is a computer software that installed in computer that may affect the performance of the computer and give attackers access to the data without the user's permission. Normally, spyware is to secretly monitors the user's behavior, collect personal information such as Internet surfing habits, sites that have been visited and others. We must regularly use the anti-spyware program to scan the computer and remove any harmful files.
5. Restrict physical and network access:
Always make sure that the sensitive and confidential data are well secured. Only allow the
authorised users to access it. We can restrict the accessment by using the biometric system. This system include fingerprints, face recognition, hand geometry, iris recognition, signature, voice recognition and etc. By limiting the access to those who really need it or requiring for it, you can protect your data.
6. Aware of mystery files:
Never open an file or attachment on a link sent to you by an unknown party. Those files and attachments can contain viruses and links which will bring harm to your computer.
Always prepare for the worst. It is very important to have a backup of your data, documents and personal information.
To know more about how to safeguard data, you can visit the following articles and links:
How password protect your financial data
How encryption works
http://en.wikipedia.org/wiki/Biometrics
http://finance.yahoo.com/banking-budgeting/article/103893/Six-Ways-to-Safeguard-Your-Online-Assets
REMEMBER...never tell anyone about your data password or let anyone get access to your personal data, even with the one who knows you.
That's all for now. See you next time!
Labels: Week 4








