How to safeguard our personal and financial data?

Filed under: by: JiA hOnG



Do you think using online services is just too darn risky? How do we safeguard our data? The manner of protection often depends on what kind of data we are safeguarding, how important or sensitive it is to us.

The following tips to help protect both our personal and financial data by protecting the computer systems that handle our data.
  1. Install a firewall- A firewall is a software program designed to allow good people in and keep bad people out. Most new computers come with intergrated into their opening system.

  2. Install and update antispyware and antivirus programs- Protect yourself against viruses and trojan horses that may steal or modify the data on your own computer and leave you vulnerable by using antivirus software. Eg, Symantec and Norton Antivirus and other popular choices.

  3. Don't open mystery attachment- Never open an attachment or click on a link sent to you by an unknown party. Attachments can contain viruses and links can lead unsuspecting users to dummy sites where they are asked to input financial information.

  4. Update your browser- Updating your browser on a regular basis can help plug up security holes, so make it a habit.

  5. Avoid accessing financial information in public- Resist logging on to check your bank balance when working from a coffee shop that offers wireless access. These systems are convenient, but also unknown. Casual users have no way of assessing how sturdy their firewalls are.

Below are tips on how to safeguard your data.

  1. Password that protect your access- Using a strong password or pass-phrase to protect access to your data.

  2. Identify where the data is stored- Having a specific places within your network or computers where you stored sensitive data. Those network shares, hard drives, servers, or system folder can then have specific protection methods used to keep them more secure.

  3. Limit physical access- Whenever possible, store sensitive data on devices that are physically secure. Only authorized individuals can access to it.
  4. Temporary data storage- If you need to store sensitive data temporarily on a memory stick, laptop, or other devices, remove that data from the device when you have finished. Ensure that data has been completely erased!

  5. Use seperate local or network account- By using seperate accounts individuals can be assigned very specific access rights and previleges. Using seperate account with differing access levels limits the potential for accidental or malicious data exposure.

The application of 3rd party certification programme in Malaysia

Filed under: by: huiwen



MSC Trustgate.com was established in 1999 as a licensed Certification Authority (CA) in Malaysia under the Digital Signature Act 1997 (DSA), a Malaysia law that sets a global precedent for the mandate of a CA. Certification Authority is the body given the license to operate as a trusted third party in the issuance of digital certificates. Trustgate provides security solutions and trusted services to help companies build a secure network and application infrastructure for their electronic transactions and communications over the network. Trustgate’s commitment in delivering high quality services has brought them recognitions with the enterprises, government, and many leading e-commerce sites, both locally and internationally. As a CA, Trustgate’s core business is to provide digital certification services, including digital certificates, cryptographic products, and software development.

Trustgate is also committed to provide the finest Public Key Infrastructure (PKI) to assist all types of companies and institutions conducting their business over the Internet.











MSC Trustgate’s Vision
Security is the primary concern of entering into the new Internet economy. The ever-changing paradigm of e-commerce requires a well-mandated security infrastructure. The vision of Trustgate is to enable organizations to conduct their business securely over the Internet, as much as what they have been enjoying in the physical world.

Being a subsidiary of Multimedia Development Corporation, Trustgate aims at catalyzing the growth of e-commerce by creating a trusted e-environment that helps businesses to expand in the new economy. Trustgate is an affiliate of VeriSign in the South East Asia region and a member of VeriSign Trust Network. This affiliation affords their customers to enjoy a globally recognized service that is compatible with the existing technological requirements .

Trustgate ID center
Trustgate provides trusted and encryption technology that secure your online communication, hence protect your vital business information from prying eyes. Trustgate is the first Malaysian Internet trust solutions company authorized to offer 128-bit SSL Server ID that is now used in financial institutions, insurance companies, e-government, healthcare organizations and other online trading. They also offer Digital ID for MyKad (Malaysian National Identity Card) that is now used in online tax filing, e-procurements and many more.

Secure Server ID (SSL Server ID)
The Secure SSL Server ID provides encryption between browser and the Web server. It is ideal for securing intranet, extranet, and Web sites.












Global Server ID (128-bit SSL Server ID)
The Global SSL Server ID gives you the strongest encryption commercially available today. E-commerce players who are serious about their business choose the 128-bit or 256 bit technology to secure the communication between their Web sites and their visitors. Global Server ID is commonly used in financial institutions, insurance companies, e-government, online merchants, healthcare organizations, and more.

Trial SSL Server ID
Over 93% of Fortune 500 companies are using VeriSign SSL Certificate to protect their e-commerce. Now you can try one free. To obtain your free SSL Trial ID, please click the link below.

MyKey (Digital ID for MyKad)
MyKey is the Digital ID that is stored inside MyKad. It provides encryption technology and digital signature capability so that the Malaysian citizen and conduct online transaction securely. MyKey is governed by Malaysia’s Digital Signature Act 1997 & is accepted by the court of laws in Malaysia. A document digitally signed with MyKey is treated as a legal binding document as it is with a handwritten signature.




The Website of MSC Trustgate:
http://www.msctrustgate.com/

The Threat of Online Security : How safe is our data?

Filed under: by: Anonymous


Recently, internet security has deteriorated markedly as there are massive computer attacks and threats on the internet. Most security threats are made by attackers using a relatively small number of vulnerabilities. Attackers, being relatively opportunistic, take the path of least resistance, and continue to take advantage of these most common failures, rather than seeking out new exploits or taking advantage of more difficult ones.

Internet threats fall under several general categories: (1) accidental actions and (2) malicious attacks. Within this latter category there are numerous subgroups, including computer viruses, denial of service attacks and distributed denial of service attacks. A third area of cyber vulnerability, online fraud, comprises issues such as identity theft and data theft.

I. Accidental Actions
Accidental actions contribute to a large number of computer security risks. This category encompasses problems arising from basic lack of knowledge about online security concepts and includes issues such as poor password choices, accidental or erroneous business transactions, accidental disclosure, and erroneous or outdated software.

II. Malicious Attacks

Attacks that specifically aim to do harm are known as premeditated or malicious attacks. They can be further broken down into attacks caused by malicious code and those caused by intentional misrepresentation.

The most common form of malicious code is a computer virus -- a program or a fragment of code that replicates by attaching copies of itself to other programs.

Denial of service attacks, another form of malicious code, are carefully crafted and executed.

III. Online Fraud

Online fraud is a broad term covering Internet transactions that involve falsified information. Some of the most common forms of online fraud are the sale via Internet of counterfeit documents, offers of easy money and prank calls, in which dial-up connections lead to expensive long distance charges.

Identity theft is a major form of online fraud, or misrepresentation. Personal identity theft on the Internet is the newest form of fraud that has been witnessed in traditional settings for many years.

Data theft is the term used to describe not only the theft of information but also unauthorized perusal or manipulation of private data.

Furthermore, the damaging threats such as viruses, spyware and adware are common occurrence.

A virus is a program or programming code that replicates by being copied or initiating its copying to another program, computer boot sector or document. Viruses can be transmitted as attachments to an e-mail note or in a downloaded file, or be present on a diskette or CD.


On the Internet, spyware is programming that is put in someone's computer to secretly gather information about the user and relay it to advertisers or other interested parties. Spyware can get in a computer as a software virus.


Adware is similar to spyware, which is software that installed on the computer ents. Adware can slow down user's personal computer and even increase the instability of user's system because many adware applications are not well-programmed. Adware has been criticized because it usually includes code that tracks a user's personal information and passes it on to third parties, without the user's authorization or knowledge.


Therefore, keep in mind that we need to safeguard our date carefully and properly. This is very important because there are now more and more online threats continuously occurred.

Phishing: Examples And Its Prevention Method

Filed under: by: Anonymous

In computing, phishing is a form of criminal activity using social engineering techniques. Phishers attempt to fraudulently acquire sensitive information, such as passwords and credit card details, by masquerading as a trustworthy person or business in an electronic communication. Phishing is typically carried out using email or an instant message. Attempts to deal with the growing number of reported phishing incidents include legislation, user training, and technical measures.

The first recorded mention of phishing is on the alt.2600 hacker newsgroup in January 1996, although the term may have appeared even earlier in the print edition of the hacker magazine 2600. The term phishing is a portmanteau of password harvesting and alludes to the use of increasingly sophisticated lures to "fish" for users' financial information and passwords; ph is a common leet replacement for f.

The best way to protect yourselves from phishing is to learn how to recognize a phish. Phishing emails usually appear to come from a well-known organization and ask for your personal information — such as credit card number, social security number, account number or password. Often times phishing attempts appear to come from sites, services and companies with which you do not even have an account.


In order for Internet criminals to successfully "phish" your personal information, they must get you to go from an email to a website. Phishing emails will almost always tell you to click a link that takes you to a site where your personal information is requested. Legitimate organizations would never request this information of you via email.


The following are some examples of phishing:

Example of HSBC



Example of PayPal



Example of myspace.com




Below is a video that explains phishing:


Approaches to Prevent Phishing Attacks


1) Detect and block the phishing Web sites in time: If we can detect the phishing Web sites in time, we then can block the sites and prevent phishing attacks. It’s relatively easy to (manually) determine whether a site is a phishing site or not, but it’s difficult to find those phishing sites out in time. Here we list two methods for phishing site detection.

  • Since the phisher must duplicate the content of the target site, he must use tools to (automatically) download the Web pages from the target site. It is therefore possible to detect this kind of download at the Web server and trace back to the phisher. Both approaches have shortcomings. For DNS scanning, it increases the overhead of the DNS systems and may cause problem for normal DNS queries, and furthermore, many phishing attacks simply do not require a DNS name. For phishing download detection, clever phishers may easily write tools which can mimic the behavior of human beings to defeat the detection.

2) Enhance the security of the web sites: The business Web sites such as the Web sites of banks can take new methods to guarantee the security of users’ personal information. One method to enhance the security is to use hardware devices. For example, the Barclays bank provides a hand-held card reader to the users. Before shopping in the net, users need to insert their credit card into the card reader, and input their (personal identification number) PIN code, then the card reader will produce a onetime security password, users can perform transactions only after the right password is input. Another method is to use the biometrics characteristic (e.g. voice, fingerprint, iris, etc.) for user authentication. For example, Paypal had tried to replace the single password verification by voice recognition to enhance the security of the Web site. With these methods, the phishers cannot accomplish their tasks even after they have gotten part of the victims’ information. However, all these techniques need additional hardware to realize the authentication between the users and the Web sites, hence will increase the cost and bring certain inconvenience. Therefore, it still needs time for these techniques to be widely adopted.


3) Block the phishing e-mails by various spam filters: Phishers generally use e-mails as ‘bait’ to allure potential victims. SMTP (Simple Mail Transfer Protocol) is the protocol to deliver e-mails in the Internet. It is a very simple protocol which lacks necessary authentication mechanisms. Information related to sender, such as the name and email address of the sender, route of the message, etc., can be counterfeited in SMTP. Thus, the attackers can send out large amounts of spoofed e-mails which are seemed from legitimate organizations. The phishers hide their identities when sending the spoofed e-mails, therefore, if anti-spam systems can determine whether an e-mail is sent by the announced sender (Am I Whom I Say I Am?), the phishing attacks will be decreased dramatically. From this point, the techniques that preventing senders from counterfeiting their Send ID (e.g. SIDF of Microsoft) can defeat phishing attacks efficiently.

4) Install online anti-phishing software in user’s computers: Despite all the above efforts, it is still possible for the users to visit the spoofed Web sites. As a last defense, users can install anti-phishing tools in their computers. The anti-phishing tools in use today can be divided into two categories which are blacklist/whitelist based and rule-based.