Showing posts with label SSL Security. Show all posts
Showing posts with label SSL Security. Show all posts

Wednesday, July 23, 2008

Recent Internet Security Threats and Predictions for 2009

Like the growth and latest developments in the technology, the worldwide internet security threat activities are also on increase. Since the day the Internet emerged to till date, the users are vulnerable to attacks by one way or the other. Though there are advanced internet security software technologies growing on the parallel side to crush or kill those internet security threats, till the spammer and the phishers are not ready to give up and continue with the phishing attacks, network-attacks & spamming by giving out malicious i.e. malfunctioning codes. Likely this sounds as a “Chase and Run” of the internet security software providers, the phishers and the spammers.
To point out, most of the internet security threats including the recent threats for 2008 is due to the malicious activity. The malicious attack or activity not only include malware attack activity but also includes phishing, pharming attack, zombie, virus, spam, malicious code, command and control over server activities and so on. The question is why these (PC’s / Computer) systems are prone to such kind of attacks? The answer is pretty simple, because they are vulnerable i.e. Susceptible to attack. So the solution bought to overcome this kind of Vulnerability is the Intrusion Prevention System, IDS in short. The IDS is nothing but the Access Control Software namely a Firewall, which prevents an intruder from entering into your system using spam bots or any other means.

The most recent on-going internet security threat attacks, where consumers use to fall prey are the data breaches which lead to identity theft. This identity theft is done when the Web browser or the plug-in or the Web application is vulnerable. Also nowadays hackers use site specific and do cross site scripting to acquire the confidential information of a user. This kind of cross scripting is done mostly for the banking sector. To resolve this kind of website or web browser vulnerabilities, the SSL (Secure Sockets Layer) certificates are being implemented to have a secure session where the website address beings with Https:// instead of Http://. Later the EV SSL Technology i.e Extended Validation SSL certificates have been initiated by a internet security software development company, known as Comodo, which formed the CAB Forum i.e. Certification Authorities and Browsers Forum to provide High Assurance stringent validation certificates. After such a hard time defense against the Zero-day attacks, patch development vulnerability, phishing attacks, pharming attacks and malicious code attacks till date of 2008, now security professionals and analysts have started working out for the internet security threat predictions for the year 2009.

As far as the prediction made, there would be more and more internet security threats would be similar to the recent threats along with the form of virus, worms, and spam bot-infections etc. And most of the attacks would be made by the phishers sector wise which involves huge financial transactions and mostly using the cross site scripting. Also Phishers have begun targeting the top countries and host companies which may result in severe attacks in future. So unless and until the user, let them be a consumer, bank, institution, or a corporate know about the vulnerabilities prevailing, the attacks can’t be prevented. So consumers need to be educated on the security measures and the authentication models before they become the victims of identity theft or network attack. To be on the safer side corporate’s also need to prevent themselves and protect their consumers to have a good business.

Thursday, June 14, 2007

EV SSL Certificates - Authentication for Sole proprietor and Small Businesses

CA/B Forum Ratifies Extended Validation (EV) SSL Certificate Guidelines to Provide Improved Online Authentication to More Businesses For Safer Online Transactions.Comodo instrumental in enabling all verifiable businesses - including sole proprietorships - to better authenticate their identities for improved customer trust and profitability

EV SSL certificates to sole proprietorships in light of the recent ratification of the EV SSL Guidelines by the CA/Browser Forum. This first ratification, two years in the making, is a milestone in the accessibility of authentication solutions for a wider range of businesses.
EV, until now, was not available to sole proprietorships and non-corporations, as the validation process only extended to corporations registered with government agencies. This put the sole proprietors at a disadvantage, as they did not have the budgets to create consumer trust through extensive brand building programs involving advertising or running "brick and mortar" retail outlets. Comodo, initiator of the CA/Brower Forum, was one of the key advocates for the extension of EV to sole proprietors, recognizing the greater level of trust they would get from EV certificates.

Background information on EV

EV SSL builds on the trust that the marketplace has in traditional SSL protection by adding an additional layer which enables the address bar in the browser to turn green, delivering visual authentication of a site's identity. Site visitors are increasingly demanding this level of identity authentication and are apt to abandon sites that do not provide it. Since EV protects users from doing business with sites that are not authentic, these EV-protected sites can be more trusted offering greater potential conversions rates, revenue and lifetime customer value.
Because of the stringent EV validation process, verifiable businesses will be able to obtain EV, while fraudsters will find it more difficult. Only a Certification Authority can issue EV SSL certificate, and before doing so, must:

1.) Verify the legal, physical and operational existence of the entity
2.) Verify that the identity of the entity matches official records
3.) Verify that the entity has the exclusive right to use the domain specified in the EV certificate, and
4.) Verify that the entity has properly authorized the issuance of the EV certificate

The standards also include rigorous auditing criteria which Certification Authorities must meet to ensure their compliance and be allowed to issue EV certificates.

For more information, visit http://www.instantssl.com/.
This new initiative will increase the Business/Sale of proprietorships and Small Business. Avail your EV SSL from Comodo - The Initiators of Trust to non-corporations.
To avail EV SSL contact sales (at) comodo (dot) com or yuvarajr (at) comodo (dot) com

Is taking a Bank Loan Good or Bad?

Definitely taking a bank loan shouldn't be a choice for you and should be the last resource if you need to. You may be wondering, why am...