Friday, February 11, 2011

Who Governs the Internet?


Basically, no one has ultimate control over the Internet. In other words, it operates without a central governing body. This is simply due to the fact that the Internet is made up from voluntarily connected networks. However, there is one corporation called the Internet Corporation for Assigning Numbers and Names (ICANN) which has more control over one aspect of the internet than any other. Click here Who governs the Internet?

ICANN is the international, self-governing body tasked with the authority to assign and control domain names and Internet Protocol (IP) addresses. The US government also has a role in controlling this system. Unfortunately, there are some issues on the Internet that ICANN had no authority over, such as pornography, gambling, and offensive writing. Click here Who governs the Internet?
.
Up till today, there is no one particular organization that has complete control or authority over the Internet. It is still governed by 3 volunteer groups:

Internet Activities Board (IAB)  - consists of Internet Engineering Task Force (IETF) and Internet Research Task Force (IRTF). IETF is responsible to develop and maintain Internet’s communication protocols, addresses problems and coordinates new services. IRTF is looks into long-term research problems that could be critical in five or ten years' time.

Internet Network Information Center (InterNic) provides various registry services needed for the Internet to operate effectively.
 
World Wide Web Consortium (W3C) is a joint initiative between the Massachusetts Institute of Technology (MIT), the European Council for Nuclear Research (or its French acronym: Conseil EuropĂ©en pour la Recherche NuclĂ©aire, CERN), andthe National Institute for Research in Computer Science and Control (or its French acronym: Institut national de recherche en informatique et en automatique, INRIA) to develop standards for the evolution of the web.

Click here Who governs the Internet?





Reference(s):

Shailendra Sial. (n.d.). Who governs the Internet? Retrieved Feb 6, 2011, from http://ezinearticles.com/?Who-Governs-the-Internet?&id=2002524

Who governs the Internet? (n.d.). Retrieved Feb 6, 2011, from http://www.webfaq.co.uk/#22

Who governs the Internet? (Aug 9, 2004). Retrieved Feb 6, 2011, from  http://www.w3concepts.com/w3Main/GoverningTheNet.htm

Thursday, February 10, 2011

The application of 3rd party certification programme in Malaysia

Normally, the third party certification offers a measure of conformity, limit supplier cost without the expense of repeat tests, and satisfy the demand of the customer. Essentially, the assessment is carried out by an independent organization. When the assessment is successfully completed, the organization will then issue the certificate. Examples of such an organization include: 


MSC Trustgate.com Sdn. Bhd is a licensed Certification Authority( CA) operating within the Multimedia Super Corrider. It was established in the year 1999. It provides fully trusted services and security solutions to help companies securely perform open business transaction ands communications over the internet network. The government, enterprises, and many leading e-commerce sites, both locally and internationally, have recognised its  commitment in delivering high quality services.


MSC Trustgate is a member of VeriSign Trust Network and an affiliate of VeriSign in the South East Asia region. MSC Trustgate also is a subsidiary of the Multimedia Development Corporation. Among its objectives is catalyzing the growth of e-commerce by  creating a trusted e-environment that helps enlarge local businesses in the new economy. Click here Security and Trust
.
My key(MyKad PKI) is accepted by the courts of law in Malaysia and governed by the Malaysia Digital Signature Act 1997. It is the MSC Trustgate. MyKey Digital Certificate which is loaded into MyKad. The advantage for MyKey is that it is a proven technology that has been deployed by 4,500 corporations and government organizations as well as 366,000 e-commerce websites worldwide. Besides that, MyKey modules include MyKey Application Programming Interface (API), Signing module, Verification module, and MyKad Client Kit.
Click here MyKad PKI(MyKey)

Verisign SSL Certificates is the one of the trusted providers of Internet infrastructure services for the networked world. Billions of times each day, domain name services, and identity and authentication services can help consumers and companies all over the world to engage in trusted communications and commerce. Verisign Identity Protection (VIP) services can help you to securely log in your personal account through online services. Two-factor authentication, a powerful validation infrastructure and self-learning fraud detection offers a cheaper and secure solution from the trust brand on the Internet offered by VIP.
.
Authentication Services allows second factor authentication for a range of OATH- compliant credential form factors. Choose from tokens, mobile phone credentials, credit-card sized credentials to provide more reasonable price and convenient options for your valuable consumers. Apart from that, consumers conveniently log in to multiple web sites through one credential also is an advantage for enterprises. The VeriSign Fraud Intelligence Network to block the potential fraud source by warning of attacts and comprehensive watchlists. VIP Fraud Detection Services automatically responds  in regards to your intervention settings and detects anomalies through a behavior engine and a rules engine. In the year 1998, the .com and .net top-level domain names have been supported by VeriSign which operates the Internet infrastructure.
.
SSL certificate, InstantSSL certificates, wildcard certificates, and Verisign certificates. Users can enjoy network security environment and a secure ecommerce base because 256 bit encryption is provided from most SSL certificate vendors. Click here Verisign Authentication Services





Reference(s):

Security and Trust. retrieved feb8,2011 from http://www.msctrustgate.com/

Verisign Authentication Services retrived feb8, 2011 from http://www.verisign.com/ 

MSC Trustgate.com.Sdn.Bhd.MyKad PKI(MyKey).  retrieved feb8, 2011 from  http://www.trademal.com/global/index.php/id/17463/target/product/task/viewdetail/cat/31626
 

Wednesday, February 9, 2011

How to safeguard our personal and financial data?


Nowadays, the internet is a very essential and common utility and communication medium to everyone. You can do many activities through the  internet, like for example, financial transactions such as online banking in order to save time and inputting our personal data into the computer. However, the internet also presents a disadvantage to the users such as when hackers and scammers can easily access your  financial data and personal information without our knowledge nor permission. Therefore, computer users must take safeguards to secure their data on the internet.

HERE ARE SOME SIMPLE SAFEGUARDS

Use security software
Anti –virus softwares such as Kaspersky, AVG and other antivirus programs can help us scan our computer and e-mails to prevent viruses from destroying our data. A firewall program, too,can preven hackers  and viruses from gaining access to your financial data and personal information without our permission. In order to be well protected, you must alway make sure that your virus definitions are up to date. Click here Internet Security - Safeguard Your Personal and Financial Data
.
Use a password and a username
Use a strong password or pass-phrase to protect against hackers who could figure out simple passwords, just by learning our IC number, handphone number, and birth date. A mix of  uppercase and lowercase numbers, letters, and symbols will offer you  more security. Click here Safeguarding your data

Avoid accessing financial information in public
It will prevent hackers from easily  logging on to check your bank balance when one is working from a restaurant that offers wireless access.

Use a credit card with a small limit
Online purchases and mail-orders easily allow a dishonest sales clerk to use your credit card information and thieves won’t be able to rack up many bills before being blocked, if one makes purchases with a low credit limit.

Approach e-mail attachments with care: Hackers and other online criminals might persuade you to share your personal information such as account number, passwords and other sensitive information through e-mail. Click here Why can't we protect our data?

Encryption: The process of encryping a message in such a way that it is expensive, time consuming, and hard for hackers to decrypt it. This process only allows the authorized person with the correct password who can see and use it. For example: the symmetric (private) key system  uses a similar key to encrypt and decrypt the message, whereas the asymmetric (public) key encryption  uses a pair of matched keys to encrypt and decrypt the message. Click here Safeguarding Your Data

Always back up important files and delete cookies: You must always back up your important financial data and personal information in a safe place. Besides that, you must preferably delete cookies after using the computer because these cookies can easily track down the password and username of the owner of the computer. Click here Why can't we protect our data?






Reference(s): 

Silki Garg. (Mar 24, 2009). Internet Security - Safeguard Your Personal and Financial Data. Retrieved Feb 8, 2011 from http://www.artipot.com/articles/312434/internet-security-safeguard-your-personal-and-financial-data.htm

MS-ISAC. (March 2007). Safeguarding your data. Retrieved Feb 8, 2011 from http://www.msisac.org/awareness/news/2007-03.cfm

Steve Schuster. (2006). Why can't we protect our data?. Retrieved Feb 8, 2011 from
http://www.educause.edu/EDUCAUSE+Review/EDUCAUSEReviewMagazineVolume41/WhyCantWeProtectOurData/158084

US-CERT. (Feb 16, 2009). Safeguarding your data. Retrieved Feb 8, 2011 from http://www.us-cert.gov/cas/tips/ST06-008.html

Tuesday, February 8, 2011

Phishing: examples and its prevention methods



Phishing is an attempt made to steal personal data like user names, passwords or credit card details using online methods, especially email, for  fraudulent purposes, otherwise known also as identity theft. The process is started by sending fake emails to you with a link to a trusted source, such as your bankWhen you enter your personal data at log-in  you are then redirected to a fake website. from where the pishers get your personal information. Another method is the phisher sends out messages with a file attachment. When you download the document which contains a virus, your computer is affected and the virus will send your personal data to the phisher.

Click on this link: http://www.ebay.com. The link will redirect you to amazon. This is an example of phishing. Click here What is Phishing – eBay Phishing Examples


Examples:-
PHISHING EMAIL
 
MESSAGE FROM EBAY MEMBER




UPDATE CREDIT CARD INFORMATION



RE-ENTER ACCOUNT INFORMATION

BANK PHISHING

 

ACCOUNT VERIFICATION



 
To prevent phishing, we have to know how to detect it. There are several ways to detect phishing messages.

  • Remember that legitimate businesses will not ask for personal information through email. If they do, that kind of email is probably a phishing email.
  • If an email asks you to "update your information" or "confirm your user and password", this is also likely a phishing message.
  • normally, phishing mail will not address you personally.
  • The email states consequences that will occur if you do not verify your details.
  • The message gives us wrong information, for example, the bank below is a building society.
  • Usually there are spelling and grammatical errors in the messages. Click here Fraudulent e-mails, are you aware?


Methods to prevent phishing are as below:
  • Always check who is sending the email
  • If there are phone number and address provided, match it with the address and the contact information provided originally by your bank.
  • Re-confirm with the bank whether they have sent any email to you.
  • use a strong password which does not display your personal data
  • Install updated antivirus and anti-spyware software
  • Never give your persosnal information by email and if  the web address begin with "https" rather than "http", this provides an additional security.
  • Don't reply to any of the emails or pop-up messages that are asking for your personal or financial information
  • Don't click on any of the links given in the suspected messages.
  • Check your credit card statements to make sure that there are no unauthorized charges in them.
  • Forward any suspected phishing e-mail to spam@uce.gov, or to the company or bank, if applicable. Click here Ways You Can Help Protect Your Computer to Avoid Phishing


Reference(s): 
Bustathief.com. (2010). What is Phishing - eBay Phishing Examples. Retrieved Feb 7, 2011 from http://www.bustathief.com/what-is-phishing-ebay-phishing-examples/


Nationwide Building Society. Fraudulent e-mails, are you aware? Retrieved Feb 7, 2011 from http://www.nationwide.co.uk/security/further-information/phishing/Fraudulent-e-mails.htm 

Jake Ruston. (Apr 1, 2010). Ways You Can Help Protect Your Computer to Avoid Phishing. Retrieved Feb 7, 2011 from http://business.ezinemark.com/ways-you-can-help-protect-your-computer-to-avoid-phishing-4efbed7ab34.html

Monday, February 7, 2011

The threat of online security: How safe is our data?

The internet is a public system where every transaction can be tracked, logged, monitored and stored in many places. Therefore, it is essential for a company or an individual who carries out business through the internet be aware of potential security threats that would easily harm their business. The same precaution applies to other individuals who are using the internet.

Online security threat occurs when some of the online users try to attack other online users by exploiting the internet's security loopholes through criminal behaviours. The following are related definitions and some of the harmful security threats on the internet.

Hacker - is the person who breaks into the computer site of the online computer users either for profit or for "challenging their security strength" purposes. Hacking simply means exploiting the vulnerabilities of the operating system.

 Malware - is a malicious software program designed to damage the computer system. Examples are viruses (or "worms") and spywares.

Virusis a form of malware that accesses a computer system by attacking it in order to disable the system or otherwise harming it in other ways with or without the knowledge of the owner. Once a computer has been attacked by viruses, it will automatically spread to all other connected computers if there are no security steps taken.  


Spyware - is intended to steal confidential data from the computer users. It can be delivered in different ways such as being attached with legitimate softwares.

 

 

Adware - is an advertising-supporting program which automatically displays advertisements on websites in a computer. These advertisements can usually be viewed through pop-up windows. 

 

 

Trojans - is a malware that is contained in a seemingly harmless program but which gets control of and harms all other programs in a computer.

 

 

Phishingtypically means stealing confidential and sensitive personal information of online users by trickery. It is usually carried out by emails.

 

 

Keylogger - is a program installed on the computer to monitor each key that a user types on the keyboard. It is usually used to collect secret and personal information such as username, password and credit card information.

.



Security threats are usually transmitted through some of these applications and program vulnerabilities:

-File sharing application
-Instant messaging
-Web servers and services
-Weak passwords
-Outdated antivirus and anti spyware programs 
Click here Security Vulnerabilities and Threats

Well, several solutions can be carried out to prevent security threats.
-Don’t open any website links that you receive from unknown users.
-Install firewalls on your gateway computer.
-Never open an email attachment from the unauthorized source.
-Install an up-to-date antivirus program and anti spyware program on your computer.
Click here Security Solutions






Reference(s):

Security risk on Internet. (n.d.). Retrieved Feb 6, 2011, from http://www.networktutorials.info/advancenetworking/internet-security-threats.html

Security threats to Ecommerce. (n.d.). Retrieved Feb 6, 2911, from http://www.exampleessays.com/viewpaper/54196.html

Thursday, February 3, 2011

E-commerce in Malaysia: implementation and application



E-commerce is increasingly becoming important and is now a common online business format on the internet. The emergence of e-commerce as an alternative medium to conduct business is changing the way that businesses are conducted in Malaysia. Examples of applications of e-commerce are in E-banking, Online Advertising, Own company Web Sites, Electronic Catalogues, Marketing by E-mail, Online Purchasing, Online Selling, Online Order Processing, Tracking or Detecting Delivery of Goods and Online Payments using Credit Card.

When implementing e-commerce, the technical issues to be considered are the Website Design, Layout, website navigation system, Technology support, shopping cart process, Search Engine Optimization, and etc. There are some requirements in maintaining e-commerce websites, including: Product updates, Presentation modifications and Search Engine Optimization revisions. To implement e-commerce successfully, we must plan in advance on how to deal effectively the web site content, pricing variables, stock management, fulfillment of orders and delivery, payment issues, policy on returns, and security support, among other matters.

With e-commerce, the transaction process is paperless because everything can be done electronically at buyers’ convenience. In the case of e-banking, Maybank launched the first Internet banking services in June 2000 and this was followed by other local banks in Malaysia. More and more, local companies nowadays opt to have an online presence with their own corporate websites to cater to a wider audience target in terms of advertising and marketing  and better customer interaction.

E-payment method is one of the issues in implementing e-commerce in Malaysia. Some merchants do not want to install specialized hardware or software to receive payments. For instance, debit card payment system is not widely used in Malaysia because most of the merchants do not want to install the hardware and software required. Security is also one of the factors that affect the application of e-commerce. Users worry that their personal information will be stolen for the purpose of identity theft or fraudulent activities.

In conclusion, although the level of adoption varies within the retail industry, the level of adoption of e-commerce is still encouraging but not extensive. There is room for improvement.







Reference(s):

Ainin S and NoorIsmawati. (2003). E-Commerce Stimuli and Practices in Malaysia. Retrieved Feb 3, 2011, from http://www.pacis-net.org/file/2003/papers/e-business/258.pdf

E-commerceAdvisor.com. (2007). E-commerce Business Plan. Retrieved Feb 3, 2011, from http://www.e-commerceadviser.com/101businessplan.php

Norudin Mansor. (2010). The Application of E-Commerce Among Malaysian Small Medium Enterprises. Retrieved Feb 3, 2011, from http://www.eurojournals.com/ejsr_41_4_11.pdf

PowerHomeBiz.com.(2010). Key Issues in Implementing an E-commerce Strategy. Retrieved Feb 3, 2011, from http://www.powerhomebiz.com/vol103/implement.htm

Wednesday, February 2, 2011

Identify and compare the revenue model for Google, Amazon.com, and eBay.

Sales revenue is the revenue received from sales of goods or services. Transaction fees are commissions paid on the volume of transactions. Subscription fees are monthly or yearly fixed amounts paid to get some services.
.
Advertising fees are payments from advertisers because they want to advertise their products or services on the particular websites. 

Affiliate fees are commissions for referring customers. These fees include cost per thousand impression (CPM), cost per click (CPC) and cost per acquisition/action (CPA).


Google
.
The revenue models of Google are subscription fees, advertising fees and affiliate fees. Google generates 99% of its revenue from advertisement. Google charges subscription fees for services. Depending on the subscription, users will automatically be charged on a monthly or yearly basis through Google Checkout. When users use Google Checkout to process their sales, they will be charged 1.9% + $0.30 per transaction.


Google uses Google AdSense as an affiliate tool to earn affiliate fee. It is a free program that empowers online publishers to earn revenue by displaying relevant ads on a wide variety of online content. Webmasters of popular sites with interesting content can sign up on Google's Adsense page and begin displaying Google advertisements to their users. Google pays the webmaster a portion of the advertising revenue and keeps the rest. Users can also promote on Google using Google Adwords.
.
Amazon.com
.
The revenue models of the company are sales revenue, transaction fees, advertising fees, subscription fees and affiliate fees. Most of the revenue of Amazon.com comes from sales revenue because it sells many things online such as books, magazines, DVDs, videos and electronics.

Sellers may put their things to sell on Amazon.com. Sellers will be charged once customers click through to the seller's website and purchase the product directly from the seller because it is a cost per click advertising program. Subscription fees applies with respect to Digital Content made available to use on a subscription basis.



EBay
.
The revenue models of eBay are transaction fees, subscription fees, affiliate fees and advertising fees. When users list an item on eBay, users are charged an insertion fee. If the item sells, they are also charged a final value fee. The basic cost of selling an item is the insertion fee plus the final value fee.

EBay is also charging subscription fees for eBay store which is a part of eBay where individual sellers can display all of the items they have for sale and tell you more about their business.  Affiliates will be paid for each click that is directed to an eBay site on a Cost per Action (CPA) model. Payment will be charged to advertisers who advertise on eBay. EBay has a few other programs such as eBay partner network and eBay affiliate program.






Reference(s):

Amazon.com. (2009). Amazon Kindle: License Agreement and Terms of Use. Retrieved Feb 1, 2011, from http://www.amazon.com/gp/help/customer/display.html?ie=UTF8&nodeId=200144530&qid=1213378239&sr=1-2  

Amazon.com. (n.d.). Explore Advertising Opportunities with Amazon.com. Retrieved Feb 1, 2011, from http://www.amazon.com/Advertising/b/?node=276241011

Bala Iyer. ( 2009). Retrieved Feb 1, 2011, from http://www.balaiyer.com/tabid/1475/bid/4501/New-revenue-model-for-Google.aspx

Boutell.Com, Inc. ( Jan 1, 2007). Retrieved Feb 1, 2011, from http://www.boutell.com/newfaq/sitespecific/googlemoney.html

eBay. (2011). About eBay. Retrieved Feb 1, 2011, from https://publisher.ebaypartnernetwork.com/files/hub/en-US/aboutEbay.html

eBay. (2011). Fees for selling on eBay. Retrieved Feb 1, 2011, from http://pages.ebay.com/help/sell/fees.html

Google. (2010). Google Checkout fees. Retrieved Feb 1, 2011, from http://checkout.google.com/seller/fees.html

Google. (2010). Subscriptions. Retrieved Feb 1, 2011, from https://checkout.google.com/support/bin/answer.py?hl=en&answer=1090911

Tuesday, February 1, 2011

An example of an E-commerce failure and its causes

One example of an e-commerce failure is Pets.com.



 

Pets.com was an online provider for pets' supplies and accessories directly to the customer over the World Wide Web. It was  launched in August 1998 but went into liquidation in 268 days. In early year 1999, however, the domain and site was purchased by a venture capitalist and it started a media advertisement blitz through the radio, television and a Pets.com magazine. Its mascot, the Pets.com sock puppet, was very famous and  became well known and the company expanded their  market and went public in February 2000. Click here: Pets.com


However, by fall 2000 the dot.com bubble burst, and despite their efforts, the company was unable to raise further capital, had to sell some of its assets as they were unable to find a purchaser or financial banker and had to shut down its operations on 9th November 2000. Click here: Pets.com goes belly up


Lack of a workable strategy plan is another reason for Pets.com to close down its business. They were always giving more discounts and free shipping to their valued customers. In fact, they were unable to turn in a profit because of the heavy cost for the shipping of bags of dog litter and cans of pet food. The company did not make any profit from the selling of merchandise because the company was selling them at about one-third of the original cost price to its customers. The company had negative gross profit margin for the first two quarters in the year 1999, while in the third quarter, net sales before operating expenses amounted to $1.62 million.  Other than that, the company was trading below $1 for the few months before it closed down its business. Click here: Pets.com


Employees who resigned from the company were not replaced which  caused the company to operate less effectively and efficiently, and was also another reason for Pets.com to close down its business.
.
.
.
.
.

Reference(s):

Austria Farmer, M. (Sept 7, 2000). Pets.com moves part of litter to Midwest. Retrieved Jan 31, 2011, from http://news.cnet.com/Pets.com-moves-part-of-litter-to-Midwest/2100-1017_3-245416.html.  

Barrett, L. (Nov 7, 2000). Pets.com goes belly up. Retrieved Jan 31, 2011, from http://news.cnet.com/Pets.com-goes-belly-up/2100-12_3-267376.html.

Junnarkar, S . (Dec 13, 1999). Pets.com to play in public market. Retrieved Jan 31, 2011, from http://news.cnet.com/Pets.com-to-play-in-public-market/2100-1040_3-234303.html.

Mast, C. (Dec 13, 2000). Living Through the Death of a Dot-Com. Retrieved Jan 31, 2011, from  http://www.businessweek.com/careers/content/dec2000/ca20001213_830.htm.

Pets.com. (Nov 7, 2010). Retreived Jan 31, 2011, from http://en.wikipedia.org/wiki/Pets.com