Thursday, December 28, 2006

What Users Do On The Internet - Why Internet Security Needed?

Increased No. of Users + Increased Internet Security = Increased Sales/Business.

Source : http://www.internetworldstats.com/top20.htm (Click Image to Enlarge)

Hope now you will understand why Internet Security is Important - Here's the Statistics for........ Click on the Image to Enlarge

Source: http://www.stanford.edu/group/siqss/Press_Release/Chart9.gif

Tuesday, December 26, 2006

EV SSL Certificates – The Real Security Measure For The Upcoming Generation

Its since the phishing/scams were more, the internet security experts and giants like Comodo and VeriSign has been working to get some more extended security to the online shoppers. With the efforts made, the EV SSL certificate is now in market to safeguard you during an online shopping / banking session.

You might have known from my previous reading whats an SSL certificate is? And would be wondering what is this EV SSL certificate - right? Here's an literature for you on the New EV SSL.

EV SSL Certificate is Extended Validation Secure Socket Layer Certificate. The name itself explains that it is more than an ordinary validation with extended technology. Security experts point out that there EV SSL's are the the next generation SSL certificate which work with advanced high security Web browsers to clearly identify a web site you visit is secure and has got a reliable business identity.

The simple difference between an SSL Certificate and an EV SSL Certificate is that a site which has got a SSL will show only the padlock as an icon of trust, whereas EV SSL turns the browsers address bar green to show the identity of the website along with the padlock. However if an website shows only the padlock it is secure but if the web site does not have an EV SSL certificate then the address bar doesn't turn green.
This new standard Extended validation SSL certificates are issued after confirming the authenticity of the authority who request the certificate, domain name ownership, verifying the business identity with government or third party business registries, and other methods/ guidelines specified CA Browser Forum to assure the legal and physical existence of the business.


The below links to the Press Releases would explain more about the EV SSL Certificates, its verification process and when its gonna to be market - And one of the releases points out “Comodo believes it could be done within two months; VeriSign worries it could take longer and is reluctant to wait.”

Click Topic ---> New 'web safe' approvals may elude small biz

Click Topic ---> Verification requires extensive checking

Thursday, November 23, 2006

SSL (Secure Socket Layer) Certificates - Process, Benefits and its Working

What is SSL?

Secure Sockets Layer protocol is a method of passing sensitive/personal information, such as credit card details, login details over the Internet. All these type of communication over the internet must be encrypted i.e. secured to prevent from hacking/identity theft. An SSL URL is preceded by https:// instead of http://.


How to create an SSL Secured website?

To be able to create a Secure SSL connection a web server requires an SSL Certificate. When you choose to install and activate an SSL certificate on your web server you need register with any of the Certification Authority (CA), where you would be prompted to complete a number of questions about the identity of your website and your company. After you fulfill the requirement of the CA’s, they would validate your business and the CA would proceed to issue you an SSL Certificate. After the validation process, your web server creates two cryptographic keys - a Private Key and a Public Key.

The word Public Key itself states that it does not need to be secret and is placed into a Certificate Signing Request (CSR) - a data file also contains your details. You would then submit the CSR. During the SSL Certificate application process, the Certification Authority (CA) will validate your details and issue an SSL Certificate containing your details and allowing you to use SSL in your web server. Your web server will match your issued SSL Certificate to your Private Key. After this process your web server would be able to establish an encrypted link / secure connection between the website and your customer's web browser.

What are the benefits of SSL?

Secure Sockets Layer or SSL for short provides the following benefits:

Authentication of the server
Whenever an customer i.e. an end user connects to an SSL enabled site, the Server sends its unique Digital certificate which is approved and signed from a universally trusted source (E.g. Comodo, Verisign or any other CA). This guarantees an end user / customer that it is being communicating with the right server.

Communication privacy
SSL uses public key as well as private key encryption technologies to provide an encrypted/secure channel. This secure channel ensures an end user / customer that all communication between the user’s browser and the Web server remains encrypted and secure so if any one intercepting the communication will only see collapsed text which would make no sense.

Which websites would require SSL?

SSL is essential when sensitive data is sent over the Internet, like and credit card info or a site which carries on with confidential and financial transactions. Such a online shopping portals, bank sites and other sites which requires to be encrypted to create trust between the user and the web server. It’s actually most secure to use SSL on all pages. But, that can slow your site down considerably. If you can’t use SSL on every page, here’s an important precaution to take.

Monday, October 16, 2006

Internet Security – Past, Present & Future

The Internet is one of the most significant achievement in the recent history.In early 1950's the idea of creating this new technology appeared. Later the implementations begin at 1960's and 1970's practically. And then at the beginning of 1980's they found and recognized the global connector Internet and it began to be spread all over the globe at the same time as well where the Internet was structured to have more than 4.3 billion potential networks. Later in 1990's the introduction of World Wide Web (WWW) began to have its common place all over the world. Now its 2K's and people though they use internet for various purposes, internet thevies have put their hands here. So its now the time to have better internet security to save the ecommerce business which is in danger. This is because the Internet without and proper security infrastructure is vulnerable to several attacks like hacking, packet sniffing, monitoring, TCP/IP hijacking, IP spoofing; and other routing infrastructure attacks. These problems exist due to the fact that Internet packets are not encrypted. Several governments across the world, however, have been trying very hard to regulate encryption on the Internet, to secure the web and the internet users being it a ecommerce merchant or an customer.

The experts aiming at internet security have been researching on some factors like, would there be a standard solution to safeguard the internet , Would the firewall, anti-virus and any other desktop security products would help to protect the PC from unwanted intruders, what type of SSL (Secure Socket layer) certificate and public key infrastructure would be appropriate to have a secure use of Internet. Would these be advantageous but to what extent and so many questions have araised for the factor of Internet security. Some of the new technologies implemented were the Smart Cards, Web Push Technology, Secure Padlock etc. This has been function well though with some drawbacks, as these technologies need some advancement in the area of storage and recognition.

The future challenges in the internet security area has got more computational intensive and also requires substantial processing power, which would possibly require to build secure intranet, Extranets, virtual networks and other internet security related applications. And if the internet security is kept in proper vigil with empowered technologies to safeguard the WWW, then the expectations of the ecommerce business would really flourish.

Please fill out this form to help you serve better: Internet Security Feedback Form

Wednesday, September 06, 2006

Internet and Ecommerce Security for Merchants and Customers

eCommerce is the conducting of business with goods and services over the Internet. Electronic commerce or e-commerce consists of the buying, selling, marketing, and servicing of products or services over computer i.e. Internet networks with the transfer of funds, through digital communications. These type of online business in using information technology industry might see it as an electronic business application aimed at commercial transactions where Electronic data Interchange or Electronic File transfer are carried out via internet. Also the supplier the customer/consumer would be transmitting inquiries, orders, invoices, payments etc. directly through their computer systems. So while these type of ecommerce transactions takes place then there is an need for internet security. In an ecommerce transaction the merchant should provide more customer security to bring more business and retain them.
The merchant / business person is always responsible for security of the Internet-connected PC where their customer details are handled. The minimum would be a Virus protection, a firewall and a commercial secure back-up where confidential information are stored.

Here are some the basic principles that needs to be a must for Customer Security.

1.) Privacy : Personal Details / Information should be kept confidential from unauthorized parties.

2.) Integrity: The information / Message which is provided should not be altered or tampered with any.

3.) Authentication: Here lies the Trust, the sender and recipient must prove their identities to each other to bring comfidence to the user & merchant.

4.) Proof of identity or Non-repudiation: An proof is needed that the message / information transmitted is indeed received by the merchant/ Customer.

The above specified principles can be done via encryption where credit cards are taken online and processed later,or credit cards are taken online and processed in real time. Its the merchant's responsibility to check the security and safety of transactions of the hosting company's webserver.

Tuesday, August 08, 2006

Are you safe and secure online?


Today, Internet growth has exploded into a latest sheer. Most of the people around the globe use the internet now for many different purposes such as a huge wave of communication through electronic mail, file transfer, transaction applications, Online Banking, Online business and much more. Thus internet appears to be more convinient and useful for the users , there are also so many technical issues surrounding the vast network of World Wide Web. One such technical issue which needs to be taken care is the Internet Security. As the usage of internet grows and grows, there are number of people who try to exploit them on web in a bad manner, unless the user is aware of how to protect themselves online.

There are sevaral hacking threats and attempts on the Internet via e-mail, Web and Instant Messaging (IM), where hackers use some malicious code - such as viruses, worms, and Trojan horses to steal personal information like passords, credit card number etc and even delete some information from an unprotected computer. A firewall can help protect your computers against these kinds of security threats and attacks. An recent study estimates that spam comprises 60 % or more of the world's e-mail traffic. So as a real human being we should pick some of the best internet security software to safeguard and secure ourselves online.

There are en-number of internet security softwares that safeguards from Internet attacks, vulnerabilities, malicious code etc. The future trends shows that a online business without proper internet security solutions would cause more damage to a company's reputation and assets as not of being a trusted source. Several security firms such as
Verisign, Comodo, Go Daddy Inc etc have helped introducing solutions such as internet security softwares, SSL – Secure Sockets Layer for web etc to carry secure online transactions.

To provide the computer/internet security the users need to effectively secure their PC now and in the future by installing some PC Desktop security softwares like Firewall, Anti-virus, Anti-Spam etc. Also online business people should install an digital certificate to ensure trust online to their customers, which my bring more business to them. Some of the leading software solutions provider such as
Comodo, ZoneAlarm provide PC security softwares for free of cost just to Create Trust Online. So our part is to identify the best solution which suits our needs and have them installed to ensure that our PC is safe and secure from hackers and phishers.
Internet has not only made the world even smaller and brought people closer but also have paved way for the rapid growth in e-commerce activities. So recommended good internet security practices will help reduce the exposure to attacks and would certainly mitigate the impact of cross-domain vulnerabilities as well. And well the interest in internet security practices will assure a successful outcome in the center stage when globally accepted.

Article Written by - R.Yuvaraj

Tuesday, July 25, 2006

Wanna report phishing..........Here's the clue

Many people though they identify a mail as a fradulent one's, they just skip as such and proceed with their work. Some reasons for this is that they don't want to spend time on reporting or they are not aware of where to report a phishing attack. Major percent of people all over the world is not aware of where to report a fradulent email or site. Here's some of anti-phishing group who fight against phishing. Ah! now you may report phishing, spam and privacy related problems in any of the group below.


1.) Anti-Phishing Working Group - http://www.antiphishing.org/


2.) Federal Trade Commission - http://www.consumer.gov/idtheft/

3.) United States CERT - http://www.us-cert.gov/nav/report_phishing.html and more.


Lets start fighting against phishing togeather and save our people from being cheated.

Is taking a Bank Loan Good or Bad?

Definitely taking a bank loan shouldn't be a choice for you and should be the last resource if you need to. You may be wondering, why am...