The application of 3rd party certificate programme in Malaysia




E-commerce is widely used around the world. In the developed country, the usage of e-commerce is extremely high as compare to Malaysia. The main issue that Malaysian does not practice e-commerce in daily life is because they feel unsecure. They are worrying that their personal details will be disclosed in the internet since there is lots of fake website and online fraud existed.

Therefore, 3rd party certification program took place to ensure the securities of users where a digital certificate issued. A digital certificate is a digital document that provides verification that your website does indeed represent your company and it will valid for a certain period of time.



MSC Trustgate

The most popular 3rd party certification program in Malaysia, MSC Trustgate.com Sdn Bhd, is corporate in 1999. It is licensed under the Digital Signature Act 1997 (DSA), a Malaysia law that sets a global precedent for the mandate of a Certificate Authority (CA). CA's goal is "To enable organization to conduct their business securely over the Internet, as much as what they have been enjoying in the physical world."


Why is the 3rd party certification needed?

Ø There are threats of internet security spreading over the net nowadays.
For example, with the increase of phishing on the internet; customers want to make sure that whether they are dealing business with a trusted party. They are afraid of their personal information such as ID number, passwords, credit card numbers and so on may be misused. Thus, the certification from 3rd party is needed to ensure their information traveled over the Internet reaches the intended recipients safely.

Ø It provides e-mail protection and validation, secure online shopping carts and more services in order to avoid being hacked and attacked by the macilious software such as virus, worms and trojan horse.

Ø More safeguard for online shopping. When the customers are confident in particular organization, it will enhance the sales in that particular company indirectly.

As a conclusion, a secure infrastructure is essential on the E-commerce in order to protect the publishers and users. The establishment of Certificate Authority plays a vital role not only to issue digital certificate but also have to ensure the security of E-commerce website. We, as an Internet users, must be aware with the security trademark to prevent from become a victim of security issues.

The threat of online security

The threat of online security

Anyone that gets online is at risk. Online security threats are one of the biggest challenges on the Internet today and most security threats are made by attackers using a relatively small number of vulnerabilities. Attackers prefer to continue to take advantage of these most common failures, rather than seeking out new exploits or taking advantage of more difficult ones.

Here are several types of threats of the online security:

1. Virus
It is a piece of code that is loaded onto your computer without your
knowledge and runs
against your wishes. Viruses can also replicate themselves and they are all manmade. A
simple virus that can make a copy of itself over and over again is relatively easy to produce.
Even such a simple virus is dangerous because it will quickly use all available memory and
bring the system to a halt.



2. Worm
A worm is similar to a virus by design and is considered to be a sub-class of a virus. Worms
spread from computer to computer. The biggest danger with a worm is its capability to
replicate itself on your system. Instead of sending out just a single worm, it could send out
hundreds or thousands of copies of itself, creating a huge devastating effect.


One example would be for a worm to send a copy of itself to everyone listed in your e-mail address book. Then, the worm replicates and sends itself out to everyone listed in each of the receiver's address book, and the manifest continues on down the line.


3. Trojan horse
A Trojan Horse is full of as much trickery as the mythological Trojan Horse it was named
after. The Trojan Horse, at first glance will appear to be useful software but will actually do
damage once installed or run on your computer. When a Trojan is activated on your
computer, the results can vary. Some Trojans are designed to be more annoying than
malicious (like changing your desktop, adding silly active desktop icons) or they can cause
serious damage by deleting files and destroying information on your system.



4. Blended Threats
Added into the mix, there is a threat named blended threat. A blended threat is a more
sophisticated attack that bundles some of the worst aspects of viruses, worms, Trojan horses
and malicious code into one single threat. Blended threats can use server and Internet
vulnerabilities to initiate, then transmit and also spread an attack. Basically it can cause
damage within several areas of your network at a time.


5. Denial-of-Service (DoS attack) or Distributed Denial-of-Service (DDoS attack)
It is used by those attackers that attempt to
prevent legitimate users from accessing
information or services to its intended users. Although the means to carry out a DoS attack may vary, it generally consists of the concerted
efforts of a person or persons to prevent an Internet site or service from functioning efficiently or at all.


The most common and obvious type of DoS attack occurs when an attacker "floods" a network with information.


6. Identity theft
It is a major form of online fraud, or misrepresentation. Personal identity theft on the Internet is the newest form of fraud that has been witnessed recently. In the online world, electronic commerce information can be intercepted as a result of vulnerabilities in computer security. Thieves can then take this information (such as credit card numbers) and do whatever they want. Identity theft can also be undertaken on a large scale, as in the case of a company or even a city.

For example, in January 2001, the entire municipality of Largo, Florida lost e-mail service for over a week when an unknown company based in Spain compromised its identity.


7. Data theft
It is the term used to describe not only the theft of information but also unauthorized perusal
or manipulation of private data. Examples of data theft abound. In 1996, a 16-year-old British
youth and an accomplice stole order messages that commanders sent to pilots in air battle
operations from the Air Force's Rome Laboratory in New York.


____________________________________________________________________

Latest news on how PayPal enhance their online security




PAYPAL offers extra online security to UK customers

Monday 26 January 2009 10.06


PayPal launches innovative security service via text message

PayPal’s customers in the UK can now opt for an extra layer of security in order to provide them safer online. The PayPal SMS Security Key texts a unique security code to the customer’s mobile phone for them to use to log in to their account. It will give further reassurance against online fraud, especially for customers who use shared computers.

This type of extra security, known as two-factor authentication, is used by several UK financial institutions to protect all their consumers against online fraud such as phishing attacks. PayPal’s SMS version has the advantage that customers who have a mobile phone don’t need to carry an extra device with them and can start using the service within minutes.

Garreth Griffith, Head of Risk Management at PayPal UK comments, “PayPal has always taken online security very seriously and is famous to keep customers’ financial information as private and confidential. As a result, successful fraud attacks on PayPal accounts are becoming very rare. But we know that some people want extra reassurance, and that’s what the PayPal Security Key will offer.

The PayPal Security Key is part of the VeriSign Identity Protection Network.
PayPal works closely with the internet industry in the fight to keep consumers safe from phishing and cybercrime. PayPal is a partner in the UK’s internet safety awareness initiative, Get Safe Online (http://www.getsafeonline.org/). PayPal works with internet service providers to stop fraudulent emails from reaching consumers: Yahoo! Mail and Google’s webmail service Gmail™ both block emails wrongly claiming to be from eBay and PayPal from reaching their customers.

Phishing


Phishing describes a method of online identity theft, in which phishers send an email to an Internet user falsely claiming to be an established legitimate organisations. When users respond to such e-mails, victims are lured to malicious web sites, where they are duped into disclosing their personal details, such as passwords and credit card, social security, and bank account numbers. In this way, phishers are able to commit identity theft, with possibly devastating consequences for the victim.


Websites that are frequently spoofed by phishers include eBay, PayPal, eBay and Yahoo.


Below is the example of a phishing scam targeting SunTrust bank customers. The email tries to trick recipients by pretending to be some sort of security alert, claims that failing to comply with the instructions may result in account suspension. As with other phishing scams, the displayed link is bogus - clicking the link actually takes the recipient to the attacker's website.



Anti-phishing measures:

  • Be cautious with confidential information and e-mails:
    Internet consumers should familiarize themselves with the way in which legitimate organizations normally communicate with their clients. Legitimate companies usually refrain from asking clients to supply sensitive personal details via e-mail. If suspicious about an e-mail message, contact the institution that supposedly sent the message and verify the origin of the message.

  • Carefully examine the URL of the websites:
    The URL displayed in the address or status bar should be examined carefully. The longer the URL, the easier it is to conceal the true destination indicated by the link. Users have to beware of cloaked links hiding the actual destination of a link.

  • Protect computers with spam filters, anti-virus, anti-spyware software, and a firewall, as well as keeping them up to date.

  • Adopt specific anti-phishing browser toolbars:
    By using a variety of technologies, dedicated toolbars are specifically designed to determine whether a site is safe, including a database of known phishing sites, analysis of the URL and the imagery and text on a site, and various heuristics.

  • Be aware of an offer that appears too good to be true:
    It probably a treat with suspicion supposed “bargains” advertised on web sites. Requests for users of online banking sites to complete an online banking survey at a monetary reward, for instance, is an example of phishing scam, in which the phishers aim to steal the banking details of the account into which the reward is to be paid .



Additional resources for everyone:


An example of an E-commerce failure and its causes






An example of business-to-consumers (B2C) failure is eToys.com.


Edward Lenk, who was previously a vice president of Walt Disney Co.began eToys, following in the footsteps of the Internet super-success Amazon.com, Inc. Lenk intention was to use the Internet to sell products in a better way. The arrival of Christmas provided him with an idea for the perfect product: toys.


EToys beat the retail chains to the Web and thus secured important deals with some of the most popular Internet Service Providers (ISPs) in 1997. However, the industry's leading competitors that led by Toys "R" Us, soon rose to the challenge and began offering toys on-line. At first, without being tied to stores, as its competitors were, the company was able to carry a light load of inventory. Unfortunetely, overoptimisic predictions for its second Christmas season caused the company to abandon this advantage, leading to its ultimate downfall.


In its second Christmas season, eToys invested large amounts, hoping that sales would double from the first Christmas season. However, the sales fell far short of expectations. By late February 2001, the company filed for bankrutcp, without a potential buyer in sight.







Potential causes for eToys.com failure:


  • Lack of business experience

Most wrong decisions were made because the founder of eToys that previously worked for the Walt Disney Corporation, but had no experience with the retail toy industry, lacked a clear understanding of business fundamentals in the areas of finance, marketing, distribution and inventory and were not able to formulate a sound business strategy which was required before the launch of any products or services in the market. Without industry-specific information and start-up experience, mortality risk increases.




  • Vulnerable financial structure (back-up funds)

The financial capital is a significant predictor of business failure. Although eToys start-ups raised funds through venture capital for initial operations, the company struggled to bring additional capital from an increasing number of reluctant investors. This affects the company ability to raise capital, as well as to finance its development by using internal resources. EToys which demonstrates a fast sales growth actually need more outside financing. The reason for this is that the company has to prepare for the increased sales by making considerable investments in equipment, manpower, raw materials and inventory, which are made before the proceeds from the sales are received. EToys failed to plan their cash needs for accelerated growth and run into financial difficulties at times that are supposed to be good from the company's point of view.



  • Slow delivery

When e-commerce was new it was unproven territory for both customers and businesses alike. The nature of demand for products and services on the Net was still not known well, and to make matters worse, customers' expectations were sky high. Because of the resulting dynamic changes posed by e-commerce, eToys was caught off guard and was too slow to respond to the changes. For example, customers in many cases expected next-day delivery from the suppliers. Suppliers, on the other hand, did not have proper back-end distribution operations in place to deliver products in a reasonable time period. Late delivery combined with the shipping and handling costs, to a certain extent, were responsible for reduced interest in online purchases. For example, eToys was accused of falling short of one of its initial goals-speedy and reliable customer service. Thousands of customers complained that their orders were either late in arriving at their destination or contained the wrong merchandise, which resulted in paying for pick-ups, refunds and reordering.




  • Inefficient promotion

The Internet has abundant free information that can be used to do effective marketing research. However, most online companies invested massively on promotion without the backing of sound market research and, thus, failed to use the most effective media to penetrate the target market for the company's products or services. EToys believed that advertisement was the key to success and acted accordingly by outrageously overspending on promotion and that, ultimately, was responsible for the demise of eToys.com.



  • Mushroom growth

Another cause of failure is the competition environment. EToy.com was competing with companies such as Toys R’ Us that had not only an online presence, but also the perceived stable infrastructure of bricks and mortar. EToys.com strategy to offer more diverse products conflicted with the strong “toy store” branding they had created. The price wars and high customer acquisition costs also caused problems for eToys.



Revenue model of Google, Amazon.com and eBay

Google’s Revenue Model:


The main source of Google’s revenue is from advertising since Google is adopting advertising revenue model, where a company provides a forum for advertisements and receives fees from the companies that advertise their products. For the 2006 fiscal year, the company reported US$10.492billion in total advertising revenues and only US$112million in licensing and other revenues. Google advertising revenue model includes Google AdWords, Google AdSense and Google Answers.

Google AdWords is pay per click advertising program of Google designed to allow the advertisers to present advertisement to people who are looking for information related to what the advertiser has to offer. Revenue is generated on a per-click advertising (having maximum amount pay per click) or placement targeted advertisements (base on CPM or CPC) for both text and banner advertisements. This program includes local, national, and international distribution. Google generate most of the revenue from Google AdWords.


Google Adsense is an ad serving program which enable text, image and, video advertisements on websites. Google AdSense includes Adsense for search and AdSense for content. Revenue is generated on a per-click or per impression basis. Besides that, the most latest is called Cost-Per-Action, was revealed via an invitation e-mail to the web site owners.


Google Answer was an experimental product for users to ger help from researches with expertise in online searching.

.
Read more information: Google revenue models , Google advertising program


Amazon.com's revenue model:


Amazon.com is an e-commerce business which generates revenue primarily by selling books, videos, electronics, and kitchen equipment on domestic and international Web sites, such as Amazon Marketplace.

Amazon.com is a pioneer of using affiliate marketing and nowadays it having about 40% of its sales is from affiliates and third party sellers who list and sell goods on the web site. Affiliate revenue model is a method whereby a company receives commissions for referring customers to others web sites by using CPM (cost per thousand impressions), CPC (cost per click) and CPA (cost per acquisition/action). Amazon Kindle is a software and hardware platform which is developed by Amazon.com web site.



Read more information: Amazon finally click


Ebay's revenue model:


EBay inc. is the world’s largest online auction site originally called Auction Web. EBay's mission is to provide a global trading platform where practically anyone can trade anything and it main source revenue is from transaction fees.EBay generates revenue from a number of fees. There are insertion fees, promotional fees, and final value fees.

  • Insertion fees: Nonrefundable fee is charged when an item is listed on Ebay.
  • Promotional fees: Fees that charged for additional listing options that help attract attention for an item, such as highlighted or bold listings.
  • Final value fees: Commission that charged to the seller at the end of the auction.

EBay also generate revenue by charging a 15% commission on the complete sale. Beside that eBay also own PayPal, Skype, and Half.com.


Read more information: About eBay, About eBay Business, Reasons to still love eBay

Other related information:
EBay vs Amazon.com, eBay vs the Google Juggernaut

History and evolution of E-commerce


Electronic commerce, more commonly known as e-commerce, is the pre-eminent buzzword of the online business revolution. It captures the excitement and focus of this fast emerging market. E-commerce systems replace all or key parts of paper-based workflow with faster, cheaper, more efficient, and more reliable communications between machines.


In the 1960's, e-commerce had already begun its evolution from concept to mega-business reality.


In 1970’s, the newly introduced Electronic Data Interchange (EDI) or Electronic Funds Transfer (EFT) allowed companies to do business over a private computer network, although at first there was no electronic protocol. However, in 1984 EDI was standardized through ASC X12. This guaranteed that companies were become stable and reliable in stable and reliable in to complete transactions with one another reliably.


Tim Berners-Lee wrote the first web browser program and invented the World Wide Web (WWW) in 1990. WWW, the Internet's client-server, opened up a new age by combining the open Internet and the easy user interface.

The year 1991 was also a pivotal year. Before 1991, commercial enterprise on the internet was strictly prohibited.


In 1994, in Internet began to become popular worldwide. In this year Netscape arrived. Giving general consumer a simple browser to surf the Internet and a safe online transaction technology called Secure Sockets Layer.


In 1995, two of the biggest names in e-commerce are launched:

  • Jeff Bezos launches Amazon.com and the first commercial-free 24 hour, internet-only radio stations, Radio HK and Net Radio start broadcasting.

  • EBay is founded by computer programmer Pierre Omidyar as Auction Web and shopping website in which business and consumer buy and sell a broad variety goods and services worldwide.

In 1998, security protocols and DSL or Digital Subscriber Line were introduced, allowing continual connection to the Internet. In January 2000, AOL or American On-Line and Time Warner announced their merger, worth over $350 million. In February 2000, many e-commerce titans including yahoo.com, amazon.com, buy.com, and e-bay.com were attacked by computer hackers. The attacks raised concerns about the security of shopping online, which the industry responded to with (obvious) security upgrades. However, e-commerce was still there to stay.

Successful model of E-commerce


Air Asia
was the first budget airline company which practiced business-to-consumer (B2C) transaction in the airline industry in Asia. Furthermore, it has been the biggest stimulator of local e-commerce activities. Since Air Asia introduced online booking air ticket through its website in May 2002 and used computer network to conduct its business operationally, it had recorded about 40% of the total revenue which were made via Internet transactions. The following are some reasons why Air Asia's E-Commerce websites flourish in the recent years.
  • Clear vision and goal
    Air Asia has a clear vison of being the largest low cost airline in Asia and serving 3 billion people who are currently underserved with poor connectivity and high fares. In the process of achieving the target, Air Asia has actually formed a dedication in building a successful online business.


  • Multi-lingual
    Air Asia is the first airline in Asian to introduce a multi-lingual website with its new Bahasa Malaysia and Mandarin websites. It is much more convenience for all races, especially in a multi-racial country like Malaysia, to book online and browse through the whole content of the site including latest promotions, new updates and information about the airline such as latest quality statistics.

  • Low Fare
    Air Asia offers very cheap ticket price for domestic as well as international flights. Therefore, Air Asia, the leading low fare airline in Asia has been expanding rapidly since 2001, to become an award winning and the largest low cost carrier in Asia.

  • Air Asia Vista Gadget
    It allows customers to instantly manage and access live travel information and web-based services directly from their Windows Vista desktop computers. With the leading-edge technology, such as Windows Vista, it enhances the customer experience with Air Asia and the quality of customer service. Moreover, the collaboration between Air Asia and Microsoft allows Air Asia to expand their marketing channels by providing instant information on AirAsia’s promotions and updates to the region.

  • Air Asia online system is conducted worldwide
    For sure, everyone can get their transaction done by using phone call, facsimile, mail and etc but Air Asia online system enables people to complete any transaction through internet. For instance, a customer from bangalore, India can book air ticket to depart from Low Cost Carrier Terminal (LCCT) to Perth, Australia.

  • Air tickets can be booked 24-7
    As long as Air Asia has a reliable e-commerce host, the web runs 24 hours a day and 7 days a week to generate sales. For examples, Air Asia usually allows customers to book free air tickets during 12 mid night.

  • Security and reliability
    Air Asia protects information and information system from unauthorized access, use, disclosure, disruption, modification, or destruction so that the customers’ data is safely kept and access to suitably controlled. All transactions will go through a secure transaction line by the company's financial institution and handled by the bank, thus, ensuring a highly secure line that will in still customers with trust.
  • Don't wait
    The Internet is evolving at a rapid pace. Obtaining a Web presence is essential, those businesses that were making huge profit margins a few years ago, are beginning to see the market flatten out with increased competition. There's still the potential to make a lot of money through e-commerce, and Air Asia is now on the track.



AirAsia.com -----> Now everyone can fly

-About Us-


*Clapssss***

Welcome to "Beat of Passion". I'm waiyin, and I will be your blogger here. I’ve started this blog because I needed a new, more eclectic bloggy home, because as much as I’d like to have some sort of unifying theme to my posts, and possibly my life, I have come to acknowledge that that’s not happening anymore. So it’s time to embrace the fact that I no longer have to direct my thoughts in any particular direction, and my mind is free to wander to its heart’s content....**Tee-Hee**


Basic information: I’m from Seremban, 5'4" tall, crave for chocolates, like sincere people and adore Robert Pattinson (best known for his role as Edward Cullen in the movie adaptation of the Twilight Series). My hobbies are hanging out with friends, swimming, watching TvB series, shopping and photography **oopz*. If i had more money, traveling would definitely be a more frequently indulged hobby.


The top five websites which I visited the most are:


That's all for my self-introduction....*
Bub-Bye*

______________________________________________________________________________






*Welcome to my Life***



Hieee…


It's EJ here!!! I'm 22 years old, from Penang, not single and not available. Currently, I'm a final year student in UTAR, major in Bachelor of Commerce (Hons) Accounting. My hobbies are window shopping, watching action and ghost movies, clubbing as well as modifying car...lol..(p/s: Anyone who is interested to go clubbing do remember to invite me...haha).

Below are the websites which i visited frequently:

_______________________________________________________________________

Hello everyone, I'm Audrey and also one of the person who take charge in managing this blog. I'm originally from Kuala Lumpur, Malaysia and I'm currently studying in University Tunku Abdul Rahman (UTAR) Sg. Long Campus. My main field of study is accountancy but i, hereby need to clarify that I'm just not as "stingy" as most people's first thought of accounting student.
I love to swim, play badminton, dancing and of course TRAVELING. As long as I can go travelling around the country / world, I will NEVER get tired easily, energetic young girl. >.<>

  • http://uk.yahoo.com/
    I surf this web approximately once a day to check my mail or even to forward/share some useful information to all my lovely friends (as quoted : sharing is caring)..
  • http://www.facebook.com/
    It's a superb website which gathers many people around the world. There are several applications which actually attracted me and there is no way for anyone who complain about the obstacles of contacting people from the other corner of the world.
  • http://www.google.com/
    I do surf this website nearly few times a day. Google has now becoming a part of my brain, it provides me most information for what I want and during assignment period, google is even closer to me than anyone else.
  • http://www.malaysiaairlines.com/my/en/home.aspx
    It's for me to check out what's the latest promotion. Moreover, I can also get the first hand information if there is 500,000 free seats fly to anywhere.
  • http://www.thestar.com.my/
    It's a very useful website. It provides me the latest information (politic, economy, society, entertainment, sports and etc).. Especially nowadays security issue has become the main concern of everyone and I gotto get myself up-to-date about what's going on in our surrounding area.


It has to come to an end for my brief introduction.

Visitors' Counter