BLOGGER TEMPLATES AND TWITTER BACKGROUNDS »

Search This Blog

Sunday, June 28, 2009

Credit Card debts: Causes and Prevention

The cost of living has increase due to the economic crisis nowadays. This crisis creates many problems that direct and indirect towards consumers. Many consumers did not have enough cash in hand is one of the reason they would choose to use the credit card. Another reason is because is an extremely convenient tool can solve their problems immediate. This kind of situation lead the number of credit card debts increase and it may lead many consumers facing the problems of bankruptcies. It is because consumer did not realized of consequences financial and non financial perspectives.

Top 3 major causes of credit card debts:

  1. Unemployment
    Some of the consumers lost their job when the bad economies. This makes them unable to maintain their living expenses such as the groceries, utilities or education fees of children in that time. Moreover, they could not find a new job during the short period forced them to use the credit card to cover their basic living expenses.
  2. Poor Money Management
    Many consumers are unaware to conduct a monthly spending plan and do not keep monthly bills or receipt to record how many money are already spend. Without keeping the bills, they would not realize how much their spending and whether their debts have rise or not. Sometimes they maybe spend unnecessarily that do not have any value to their life.
  3. No saving cushion
    Most consumers using the future money when using the credit card and do not have extra money to save in bank. Besides that, they don’t understand the benefits of how money works and grows or how to save and invest the money for the emergency needs or expenses.

Prevention methods

  1. Making a budget plan
    Every person need to have a budget plan especially those credit card holders. This can help consumers to perceive that they will avoid the unnecessarily spending or will not overspending their budget. This plan must set before and prevent from the debts.
  2. Self control and discipline
    Have a direct set up is one of the best practices so that able to pay back the full amount each month and for emergency use only. Like this way, consumers can control themselves by limit the credit card amount and learn not to overspend more than their limit budget every month.
  3. Cash transaction
    Another way is stop charging items on the credit card and use cash to make transaction for the items they buy. Then the consumers do not need to pay the extra charges for the credit card debts.

Friday, June 26, 2009

Phishing: Examples And Its Prevention Methods



What Is Phishing?


In the field of computer security, phishing is a form of criminal activity using social engineering techniques. Phishing is the criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication. Communications purporting to be from popular social web sites, auction sites, online payment processors or IT Administrators are commonly used to lure the unsuspecting public. Phishing is typically carried out by e-mail or instant messaging, and it often directs users to enter details at a fake website whose look and feel are almost identical to the legitimate one. Even when using server authentication, it may require tremendous skill to detect that the website is fake.

You might see a phishing scam:

•

In e-mail messages, even if they appear to be from a coworker or someone you know.

•

On your social networking Web site.

•

On a fake Web site that accepts donations for charity.

•

On Web sites that spoof your familiar sites using slightly different Web addresses, hoping you won't notice.

•

In your instant message program.

•

On your cell phone or other mobile device.


Often phishing scams rely on placing links in e-mail messages, on Web sites, or in instant messages that seem to come from a service that you trust, like your bank, credit card Company, or social networking site.

Typically, phishing attacks will direct the recipient to a web page designed to mimic a target organization’s own visual identity and to harvest the user's personal information, often leaving the victim unaware of the attack. Obtaining this type of personal data is attractive to black hats because it allows an attacker to impersonate their victims and make fraudulent financial transactions. Victims often suffer significant financial losses or have their entire identity stolen, usually for criminal purposes. As a successful and lucrative form of financial fraud, phishing made its mark on the networked landscape in 2004. Today, it is a booming segment of the identity theft “industry”. In January of 2004, there were 174 phishing Web sites identified by the cross-vendor Anti-Phishing Working Group. By December, there were over 1700. Finally, that year, the reported consumer loss due to Internet-based fraud was estimated between US$500 million (according to the Federal Trade Commission) and US$2 billion (according to the Anti-Phishing Working Group). Financial institutions and law enforcement agencies alike were ill-prepared to deal with organized, technically literate, internationally-based criminals.


Examples of Phishing Scam


Web sites that are frequently spoofed by phishers include PayPal, eBay, MSN, Yahoo, Best Buy, and America Online.

This phish claims that Washington Mutual Bank is adopting new security measures which require confirming ATM card details. As with other phishing scams, the victim is directed to visit a fraudulent site and any information entered on that site is sent to the attacker.

The email warns that failing to comply with the instructions may result in account suspension. Note the use of the SunTrust logo.This is a common tactic with 'phishers' who often use valid logos they have simply copied from the real banking site in an attempt to lead credence to their phishing email.

As with the SunTrust example, this eBay phishing email includes the eBay logo in an attempt to gain credibility. The email warns that a billing error may have been made on the account and urges the eBay member to login and verify the charges.

There is no shortage of irony in the Citibank phishing example. The attacker claims to be acting in the interests of safety and integrity for the online banking community. Of course, in order to do so, you are instructed to visit a fake website and enter critical financial details that the attacker will then use to disrupt the very safety and integrity they claim to be protecting.

As seen with the previous Citibank phishing scam, the Charter One phishing email also pretends to be working to preserve the safety and integrity of online banking. The email also includes the Charter One logo in an attempt to gain credibility.

PayPal and eBay were two of the earliest targets of phishing scams. In the example, this PayPal phishing scams tries to trick recipients by pretending to be some sort of security alert. Claiming that someone 'from a foreign IP address' attempted to login to your PayPal account, the email urges recipients to confirm their account details via the link provided.

As with other phishing scams, the displayed link is bogus - clicking the link actually takes the recipient to the attacker's website.A security flaw on a US government website has been exploited by a phishing scam claiming to be an IRS refund notification. The phishing email claims the recipient is eligible for a tax refund of $571.94. The email then tries to gain credibility by instructing recipients to copy/paste the URL rather than clicking it. That's because the link actually does point to a page on a legitimate government website, http://www.govbenefits.gov. The problem is, the page being targeted on that site allows the phishers to 'bounce' the user to another site altogether.


Prevention methods


There are several (technical or non-technical) ways to prevent phishing attacks:

  • Educate users to understand how phishing attacks work and be alert when phishing-alike e-mails are received;
  • Use legal methods to punish phishing attackers;
  • Use technical methods to stop phishing attackers.


Social Responses


Users who are contacted about an account needing to be "verified" can take steps to avoid phishing attempts, by contacting the company that is the subject of the email to check that the email is legitimate, or by typing in a trusted web address for the company's website into the address bar of their browser, to bypass the link in the suspected phishing message. The Anti-Phishing Working Group, an industry and law enforcement association has suggested that conventional phishing techniques could become obsolete in the future as people are increasingly aware of the social engineering techniques used by phishers. They propose that pharming and other uses of malware will become more common tools for stealing information.


Legal Responses


Microsoft has joined the effort to crack down on phishing. On March 31, 2005, Microsoft filed 117 federal lawsuits in the U.S. District Court for the Western District of Washington. The lawsuits accuse "John Doe" defendants of using various methods to obtain passwords and confidential information. March 2005 also saw Microsoft partner with the Australian government to teach law enforcement officials how to combat various cyber crimes, including phishing. Microsoft announced a planned further 100 lawsuits outside the U.S. in March 2006.


Technical Responses


If we can cut off one or several of the steps that needed by a phishing attack, we then successfully prevent that attack.

  • Detect and block the phishing websites in time:

If we can detect the phishing Web sites in time, we then can block the sites and prevent phishing attacks. It’s relatively easy to (manually) determine whether a site is a phishing site or not, but it’s difficult to find those phishing sites out in time.

  • Enhances the security of the websites:

One method to enhance the security is to use hardware devices. Another method is to use the biometrics characteristic (e.g. voice, fingerprint, iris, etc.) for user authentication. With these methods, the phishers cannot accomplish their tasks even after they have gotten part of the victims’ information. However, all these techniques need additional hardware to realize the authentication between the users and the Web sites hence will increase the cost and bring certain inconvenience. Therefore, it still needs time for these techniques to be widely adopted.

  • Block the phishing e-mails by various spam filters:

The phishers hide their identities when sending the spoofed e-mails, therefore, if anti-spam systems can determine whether an e-mail is sent by the announced sender, the phishing attacks will be decreased dramatically. From this point, the techniques that preventing senders from counterfeiting their Send ID can defeat phishing attacks efficiently. The spoofed e-mails used by phishers are one type of spam e-mails. From this point of view, the spam filters, can also be used to filter those phishing e-mails. Most of these anti-spam techniques perform filtering at the receiving side by scanning the contents and the address of the received e-mails. Furthermore, spam filters are designed for general spam e-mails and may not very suitable for filtering phishing e-mails since they generally do not consider the specific characteristics of phishing attacks.

  • Install online anti-phishing software in user’s computers:

Despite all the above efforts, it is still possible for the users to visit the spoofed Web sites. As a last defense, users can install anti-phishing tools in their computers. The anti phishing tools in use today can be divided into two categories: blacklist/white list based and rule-based.


Related links:

  1. http://en.wikipedia.org/wiki/Phishing
  2. http://searchsecurity.techtarget.com/sDefinition/0,,sid14_gci916037,00.html
  3. http://www.honeynet.org/papers/phishing/
  4. http://www.microsoft.com/protect/yourself/phishing/identify.mspx
  5. http://antivirus.about.com/od/emailscams/ss/phishing_9.htm
  6. http://y2u.co.uk/Knowledge_Information/Technology/RN_Computer_Phishing_Scam.htm
  7. http://research.microsoft.com/en-us/um/people/chguo/phishing.pdf

Tuesday, June 23, 2009

How to safeguard our personal and financial data?

Internet is very common in nowadays. Every person need to use computer to complete their task or job everyday. They all rely on computer to save our personal data and through online financial services to do the financial transaction such as online payment, online banking to save time.

It is very convenient but internet is not a safe place especially for those people using online banking or payment. It is because hackers have the expertise and ability to intercept and do falsely when they using the information such as credit card numbers. So we need to take some prevention to increase internet security and decrease the probability of data being stolen. There are some suggestions stated in below:

  1. Avoid using password that easy for memorize, use those password hardly to guess by other people. Beside that, don’t write down the password and carry it in your wallet. Use combination of numbers and letters if it possible
  2. Install or use updated antispyware and antivirus software to protect. For example, Symantec, Norton and Avg antivirus are most popular software use by computer users. Its clean computer and protect personal information, financial data and etc.
  3. Avoid accessing financial information in public. User must avoid logging in to check its own bank account or other sensitive personal data when using a free wireless connection that outside coffee shop, airports and other public places provided.
  4. Biometric device. Biometric devices using some biometric identifier to access program, computers or rooms to safeguard our own personal and financial data. Those biometric devices include fingerprint scanners, hand geometry systems, face recognition systems, voice verification systems, signature verification systems and iris recognition systems. Advantages of using this method is the data won’t lose although it is being stolen.

Additional informations:
1) Six ways to safeguard your online assets
2) Keep your financial data safe online
3) http://www.us-cert.gov/cas/tips/ST06-008.html
4) http://www.msisac.org/awareness/news/2007-03.cfm

Sunday, June 21, 2009

An example of an E-commerce success and its cause


For example - eBay


eBay is a global online marketplace where practically anyone can trade practically anything. Launched in 1995, eBay started as a place to trade collectibles and hard-to-find items.


eBay founded in Pierre Omidyar's San Jose, a computer programmer, wrote the code for an auction website that he ran from his home computer in September 1995. It was from start meant to be a marketplace for the sale of goods and services for individuals.


Today, eBay is the world's largest online community of buyers and sellers. With a global presence in 38 markets, including the US, and over 241 million registered users worldwide, eBay offers boundless opportunity to come together in one Internet site and be able to buy and trade a wide range of items, including fine collectibles. It allows people pursue their interests and their passions in the areas of their hobbies and their collectibles.


eBay has built an online person-to-person trading community on the Internet, using the World Wide Web. Buyers and sellers are brought together in a manner where sellers are permitted to list items for sale, buyers to bid on items of interest and all eBay users to browse through listed items in a fully automated way. The items are arranged by topics, where each type of auction has its own category. It's convenient and easy to be found by people.


eBay has both streamlined and globalized traditional person-to-person trading, which has traditionally been conducted through such forms as garage sales, collectibles shows, flea markets and more, with their web interface. This facilitates easy exploration for buyers and enables the sellers to immediately list an item for sale within minutes of registering.


eBay has done a regular basis to promote eBay, they have had isolated campaigns through radio and print, and they've also done some tradeoffs and some banner ads on other sites. But the really unique thing about eBay is that when compare theirs to traditional businesses or other e-commerce sites, they have done very little external promotion to build membership.


eBay is such a unique community that they've been able to build their membership through the word-of-mouth of their users and they've also attracted new members due to the amount of media attention that has come to the site in the past few years.

Another cause has helped to make eBay as successful as it has been, is that people really enjoy the experience of the shopping bazaar. They enjoy looking around for merchandise. The other component is they really enjoy the competition of the bidding process. Everybody likes to get a bargain, and in some way, shape or form, likes to haggle a little bit over the price. eBay's auction format allows users to do that.


Obviously, people are becoming more and more comfortable with shopping online and they're getting more and more accustomed to doing that. That's another factor why eBay is grateful.