Thursday, February 12, 2009

The application of pre-paid cash card for consumers



Prepaid cash cards are plastic cards, which fall under the pay first category of plastic payments. Prepaid cash cards can be used to make payment for goods and services and even to withdraw money. Before use, the user needs to load the card with a sum of money. This means there is no risk of running into debt as it has no credit or overdraft facility. Prepaid cash cards are designed to be used as a safer alternative as compare to cash.

The prepaid cash card is of use in several ways. For example, we can use it for paying bill, such as rent, utilities, insurance, car payment, and cell phone bills. Besides, we can shop at anywhere as long as the card using is accepted at different retailers, buys fuel at the pump, pay by phone, and shop on the Internet. We also can use it for transferring money - for some prepaid cash card they provide the convenient such as send or receive money via bank wire transfers, between two cards.

The following are some examples of the prepaid cash card:

Touch ‘n Go (TnG) smart card is used by Malaysian for electronic payment system to toll expressway and highway. It is expanding its business to retail purchase by starting with fast food industry that enables consumers to buy dough nut, burger or fast-food from 21 outlets such as Burger King, 7-Eleven, Dunkin’ Donut. It is imitating the success of Hong Kong’s Octopus Card by setting 5 to 10% of the card holders for retail purchase as current target of the company.

Octopus Card was launched in Hong Kong on year 1997, September. It is a rechargeable contactless stored value smart card to transfer electronic payments in online in offline system. It is widely used in payment system for transportation, supermarkets, fast food restaurant, car parks and other pint of sale application such as service station s and vending machines that have achieved good outcomes.

Monday, February 9, 2009

The threat of online security: How safe is our data?

The threat of online security: How safe is our data?

The threat of online security can be distinguish between nontechnical and technical.

Nontechnical attacks are those in which a perpetrator uses some form of deception or persuasion to trick people into revealing information or performing actions that can compromise the security of a network. Examples are pretexting and social engineering.

Technical attack is an attack perpetrated using software and system knowledge or expertise. An example of technical attack is a computer worm.

Types of attacks
Zero-day incidents are attacks through previously unknown weaknesses in their computer network.

Denial of service is an attack in which so many requests for service or access bombard a system that it crashes or cannot respond. Zombied PCs can be used to launch DOS attacks or spread adware.

Phishing is a crimeware technique to steal the identity of a target company to get the identities of customers.

Web servers and web pages can be hijacked and configured to control or redirect unsuspecting users to scam or phishing sites.

A botnet is a huge number of hijacked Internet computers that have been set up to forward spam and viruses to other computers on the Internet.

A virus is a piece of software code that inserts itself into a host, including the operating systems, running its host program activates the virus.

A worm is a software program that runs independently, consuming the resources of its host in order to maintain itself, that is capable of propagating a complete working version of itself into another machine.

A macro virus is a virus or worm that executes when the application object that contains the macro is opened or a particular procedure is executed.

Trojan horse is a program that appears to have a useful function but that contains a hidden function that presents a security risk.

Trojan-Phisher-Rebery is a new variant of a Trojan program that stole tens of thousands of stolen identities from 125 countries that the victims believed were collected by legitimate company.

Banking Trojan is a Trojan that comes to life when computer owners visit one of a number of online banking or e-commerce sites.
Rootkit is a special Trojan Horse program that modifies existing operating system software so that an intruder can hide the presence of Trojan program.

Saturday, February 7, 2009

Phishing - examples and its prevention methods

Phishing is an e-mail fraud method in which the perpetrator sends out legitimate-looking email in an attempt to gather personal and financial information from recipients. Typically, the messages appear to come from well known and trustworthy Web sites such as PayPal, eBay and Yahoo. A phishing expedition, like the fishing expedition it's named for, is a speculative venture: the phisher puts the lure hoping to fool at least a few of the prey that encounter the bait.

Examples of phishing:
(1) PayPal


(2) eBay

(3) Yahoo!


How to prevent phishing?

Don’t click on links within emails that ask for your personal information.
Fraudsters use these links to lure people to phony Web sites that looks just like the real sites of the company, organization, or agency they’re impersonating. If you follow the instructions and enter your personal information on the Web site, you’ll deliver it directly into the hands of identity thieves. To check whether the message is really from the company or agency, call it directly or go to its Web site (use a search engine to find it).


Never enter your personal information in a pop-up screen.
Sometimes a phisher will direct you to a real company’s, organization’s, or agency’s Web site, but then an unauthorized pop-up screen created by the scammer will appear, with blanks in which to provide your personal information. If you fill it in, your information will go to the phisher. Legitimate companies, agencies and organizations don’t ask for personal information via pop-up screens. Install pop-up blocking software to help prevent this type of phishing attack.

Protect your computer with spam filters, anti-virus and anti-spyware software, and a firewall, and keep them up to date.
A spam filter can help reduce the number of phishing emails you get. Anti-virus software, which scans incoming messages for troublesome files, and anti-spyware software, which looks for programs that have been installed on your computer and track your online activities without your knowledge, can protect you against pharming and other techniques that phishers use. Firewalls prevent hackers and unauthorized communications from entering your computer – which is especially important if you have a broadband connection because your computer is open to the Internet whenever it’s turned on. Look for programs that offer automatic updates and take advantage of free patches that manufacturers offer to fix newly discovered problems.

Only open email attachments if you’re expecting them and know what they contain.
Even if the messages look like they came from people you know, they could be from scammers and contain programs that will steal your personal information.

Be suspicious if someone contacts you unexpectedly and asks for your personal information.
It’s hard to tell whether something is legitimate by looking at an email or a Web site, or talking to someone on the phone. But if you’re contacted out of the blue and asked for your personal information, it’s a warning sign that something is “phishy.” Legitimate companies and agencies don’t operate that way.

Act immediately if you’ve been hooked by a phisher.
If you provided account numbers, PINS, or passwords to a phisher, notify the companies with whom you have the accounts right away.


Report phishing, whether you’re a victim or not.
Tell the company or agency that the phisher was impersonating. You can also report the problem to law enforcement agencies. The information you provide helps to stop identity theft.

Friday, February 6, 2009

the way to safeguard our personal and financial data

Nowadays, the computer and internet is very common to everyone. Most of the people will rely on computer to save their own data and using online financial service to do their financial transaction such as online e-banking. However, the information transmitted over the Internet is more vulnerable and has a higher degree of security risk than internal networks because they are open to anyone. For-example, the other people will easily know your bank account number if the hacker was incursion to the bank system. Therefore, safeguard of computer is important for the users to protect their data.

Here are some suggestions for the computer users to safeguard their data:
1. Password protection
The users may create some longer password because it is more security compare to the shorter password. Other than that, users may change the password frequently and do not disclose to other people, including friends and family.

2. Install and update antispyware and antivirus programs
Install an antivirus program such as Symantec and Norton antivirus, AVG antivirus or other more in order to protect theirself against viruses and Trojan horses that may steal or modify the data on their computer. The antivirus must be always up to date in order to keep the well protection.

3. Avoid accessing financial information in public
The users do not encourage to log in to the bank system to check the balance from the coffee shop that provide wireless access. This is because we don’t know how powerful their firewalls are.

4. Biometric device
It’s grant access to programs, computers or rooms using computer analysis of some biometric identifier. The examples of biometric devices and systems include fingerprint scanners, hand geometry systems, face recognition systems and others. The biometric devices are gaining popularity as a security precaution because they are a virtually foolproof method of identification and authentication.

5. Encryption
The individuals may use a variety of encryption techniques to keep data secure and private. Encryption is a process of converting readable data into unreadable characters to prevent unauthorized.

Related links:
1.http://www.us-cert.gov/cas/tips/ST06-008.html
2.http://www.msisac.org/awareness/news/2007-03.cfm
3.http://finance.yahoo.com/banking-budgeting/article/103893/Six-Ways-to-Safeguard-Your-Online-Assets

Thursday, February 5, 2009

The application of third party certification programme in Malaysia


The most famous application of third party certification programme in Malaysia is provided by the MSC Trustgate.com Sdn Bhd. MSC Trustgate.com Sdn Bhd is a licensed Certification Authority (CA) operating within the Multimedia Super Corridor. MSC Trustgate was incorporated in 1999 to meet the growing need for secure open network communications and become the catalyst for the growth of e-commerce, both locally and across the ASEAN region. They offer complete security solutions and leading trust services that are needed by individuals, enterprises, government, and e-commerce service providers using digital certificates, digital signatures, encryption and decryption. Their vision is to enable organizations to conduct their business securely over the Internet, as much as what they have been enjoying in the physical world.


The products and services of Trustgate are SSL Certificate, Managed PKI, Personal ID, MyTRUST, MyKAD ID, SSL VPN, Managed Security Services, VeriSign Certified Training and Application Development. Digital certificate usually attach to an e-mail or an embedded program in a web page which verifies that user or website is who they claim to be. The common functions of a digital certificate are user authentication, encryption and digital signatures. User authentication provides other security than using username and password. Its session management is stronger. Encryption can make the data transmission secured by using the information encrypted. The intended recipient of the data is only person to receive the message. Digital signatures are like the hand signature in the digital world. It can ensure the integrity of the data. By using the digital certificate, the users will be able to make transaction on the internet without fear of having the personal data being stolen, information contaminated by third parties, and the transacting party denying any commercial commitment with the users. Furthermore, the digital certificates can assist the development of greater internet based activities.

Saturday, January 31, 2009

Revenue model for Google, Amazon.com, eBay

5. Identify and compare the revenue model for Google, Amazon.com, eBay.
Google has multiple revenue models. It earns profit from advertising fees, from functions such ad AdWords, a pay per click advertising programme which allows advertiser shows relevent or related advertisement from what users searching for. As you can see, AdWords also generates affiliates fee for Google.
Google also have another revenue model which also an advertising form call AdSense. Website owners can enroll in the program to enable text and vidoe advertisements. This has same concept as pay per click, advertisers are required to pay Google a fee for each time a user clicks on the advertisement.
eBay does not have inventory like Amazon.com. It only provides technology platforms and tools for e-commerce. ebay has various revenue model, it earns transaction fee from owning paypal, an online paying service system for users to buy items online more conveniently. ebay also gains sales from the service of listing customer’s product to be sold to other users as well as some advertisement fee. ebay generated overall revenue around $6 billion from its three primary business: auctions, payments (PayPal) and communication (Skype).
Amazon.com uses similar revenue model to ebay, they also offer items listing to be sold online. Amazon.com generate revenue from commissions from suppliers when there is a sale of product. In thier main websites, there are few advertisement displays in the page where users browsing through some items.

Thursday, January 29, 2009

Google's success and its causes

The first name that comes to most peoples’ mind when they want to use a search engine on the web is ‘Google’. Google has paved the way globally for technological innovation, business prudence, product quality and effective marketing. Google’s success hasn’t been gained overnight. Instead, it has been a combination of foresight, good business thinking, product innovation and of course luck. Here are ten things, which could potentially benefit companies aspiring to achieve success just like Google did, in their industry.

1. A unique product

Google was successful because it made good business decisions, constantly improving its products as well as expanding its product base. But at the core of its business was and still is a very unique, solid and effective search engine more popular than any search engines currently in the market. The point is that even before delving into competitive pricing and effective marketing strategies it is important that you offer something, which most companies in the same industry don’t. It may be a product or even a service.

2. Focus on core competency first

Google has always focused on keeping its original products robust and on the leading edge of technological advancement. This helps them invest in other areas without putting themselves at too much risk.

3. The battle against inertia

Google was very successful with its core product, the search engine, but it didn’t stop there. They kept improving it while constantly probing non-traditional markets such as mobile services (SMS service), desktop searches (Windows search has been used traditionally with a Windows OS), etc. For a company it is necessary to keep making better its current products but at the same time it is equally important to look out for new markets and opportunities because the competition is most certainly doing that!

4. Getting the right people

Your company is only as good as the people who work for it. Google carefully chose its people because they wanted to make sure that the people coming in were mentally aligned to the company's goals and objectives. Not only should they have the necessary skill sets to adjust to the culture and perform in it, but they should thrive in this environment. For Google, the important qualities to look for in potential employees were creativity and imagination more than experience and education.

5. The best defense is offense

Google recently launched their web document tools such as Google spreadsheets and documents. Microsoft has dominated the offline market for the longest time and though this does not look like a direct hit it does make them think and put a foot back in defense. It pays to be proactive instead of being reactive. Penetrating into foreign territory with aggressiveness but with sufficient research and logic will more often than none lead to sustained growth.

6. Promote the right culture and then embrace it

People popularly know the Googleplex today, the Google HQ boasts of state-of-the-art facilities that has everything from swimming pools and hair stylists to a multi-cuisine cafeteria and day-care center. It is because Google wants its employees to feel more than just employees and their work place more than just a cubicle with a desk and a computer. Google promotes a ‘family’ environment with all the comforts of a home and more. Because the philosophy is that a happy, free and content mind is a creative, imaginative mind free of day-to-day stress and problems.

7. Speed to market

In today’s environment, speed to market can make or break your company or at least cause significant damage or enormous profitability. Google has an unusual strategy in that it releases beta products very quickly in the mainstream user market while it contemplates on financing strategies and product quality. They buy time but make sure the consumers get a taste of the product, so that by the time it is ready to sell it; users are hooked on to it. Speed is important and it pays off. The thing to remember though that speed to market should not be confused with hastiness, which could have a hard-hitting backlash instead of potential profitability.

8. Be honest to your company’s mission statement

Google’s mission statement explains their desire to make quality data universally available. For the same reason they never insert ads into their search hits. In fact when AOL first wanted to use Google’s search engine capabilities on their website it asked them to insert ads. They refused and have steered clear of it ever since. They got the contract with AOL two years later. Your company needs to understand and value what it stands for and function by it. Publicly owned companies will soon lose shareholder confidence if they exhibit hypocrisy in business practices.

9. Find the right investors

If your company is really a start-up looking for promising investors then the importance of getting the right-minded (for your company) investors cannot be stressed more. It doesn’t make good business sense to approach pharmaceutical companies for funding when your company is all about IT, at least in most cases, unless there is a vested interest. These investors often sit at the Board of Directors meetings and have a yay or nay in a lot of crucial decisions.

10. Believe in Luck!

Believe it or not luck is important too, the lack of which can cause serious damage. But it doesn't means that the company should sit back leaving itself to the mercy of fortune.Though you can never achieve ‘good luck’ you can certainly align your decisions in a way that would make it more likely to be lucky than unlucky. Looking at long-term losses instead of immediate gains while making decisions is imperative.