Showing posts with label Online Shoping. Show all posts
Showing posts with label Online Shoping. Show all posts

Sunday, September 5, 2010

A Strong Password Isn't The Strongest Security

Make your password strong, with a unique jumble of letters, numbers and punctuation marks. But memorize it, never write it down. And, oh yes, change it every few months. These instructions are supposed to protect us. But they don’t!

Some computer security experts are advancing the heretical thought that passwords might not need to be “strong,” or changed constantly. They say onerous requirements for passwords have given us a false sense of protection against potential attacks. In fact, they say, we aren’t paying enough attention to more potent threats.


Here’s one threat to keep you awake at night: Keylogging software, which is deposited on a PC by a virus, records all keystrokes — including the strongest passwords you can concoct — and then sends it surreptitiously to a remote location.

“Keeping a keylogger off your machine is about a trillion times more important than the strength of any one of your passwords,” says Cormac Herley, a principal researcher at Microsoft Research who specializes in security-related topics. He said antivirus software could detect and block many kinds of keyloggers, but “there’s no guarantee that it gets everything.”

After investigating password requirements in a variety of settings, Mr. Herley is critical not of users but of system administrators who aren’t paying enough attention to the inconvenience of making people comply with arcane rules. “It is not users who need to be better educated on the risks of various attacks, but the security community,” he said at a meeting of security professionals, the New Security Paradigms Workshop, at Queen’s College in Oxford, England. “Security advice simply offers a bad cost-benefit tradeoff to users.”

One might guess that heavily trafficked Web sites — especially those that provide access to users’ financial information — would have requirements for strong passwords. But it turns out that password policies of many such sites are among the most relaxed. These sites don’t publicly discuss security breaches, but Mr. Herley said it “isn’t plausible” that these sites would use such policies if their users weren’t adequately protected from attacks by those who do not know the password.

Mr. Herley, working with Dinei FlorĂȘncio, also at Microsoft Research, looked at the password policies of 75 Web sites. At the Symposium on Usable Privacy and Security, held in July in Redmond, Wash., they reported that the sites that allowed relatively weak passwords were busy commercial destinations, including PayPal, Amazon.com and Fidelity Investments. The sites that insisted on very complex passwords were mostly government and university sites. What accounts for the difference? They suggest that “when the voices that advocate for usability are absent or weak, security measures become needlessly restrictive.”

Donald A. Norman, a co-founder of the Nielsen Norman Group, a design consulting firm in Fremont, Calif., makes a similar case. In “When Security Gets in the Way,” an essay published last year, he noted the password rules of Northwestern University, where he then taught. It was a daunting list of 15 requirements. He said unreasonable rules can end up rendering a system less secure: users end up writing down passwords and storing them in places that can be readily discovered.

“These requirements keep out the good guys without deterring the bad guys,” he said.

Northwestern has reduced its password requirements to eight, but they still constitute a challenging maze. For example, the password can’t have more than four sequential characters from the previous seven passwords, and a new password is required every 120 days.

By contrast, Amazon has only one requirement: that the password be at least six characters. That’s it. And hold on to it as long as you like.

A short password wouldn’t work well if an attacker could try every possible combination in quick succession. But as Mr. Herley and Mr. FlorĂȘncio note, commercial sites can block “brute-force attacks” by locking an account after a given number of failed log-in attempts. “If an account is locked for 24 hours after three unsuccessful attempts,” they write, “a six-digit PIN can withstand 100 years of sustained attack.”

Roger A. Safian, a senior data security analyst at Northwestern, says that unlike Amazon, the university is unfortunately vulnerable to brute-force attacks in that it doesn’t lock out accounts after failed log-ins. The reason, he says, is that anyone could use a lockout policy to try logging in to a victim’s account, “knowing that you won’t succeed, but also knowing that the victim won’t be able to use the account, either.” (Such thoughts may occur to a student facing an unwelcome exam, who could block a professor from preparations.)

Very short passwords, taken directly from the dictionary, would be permitted in a password system that Mr. Herley and Stuart Schechter at Microsoft Research developed with Michael Mitzenmacher at Harvard.

At the Usenix Workshop on Hot Topics in Security conference, held last month in Washington, the three suggested that Web sites with tens or hundreds of millions of users, could let users choose any password they liked — as long as only a tiny percentage selected the same one. That would render a list of most often used passwords useless: by limiting a single password to, say, 100 users among 10 million, the odds of an attacker getting lucky on one attempt per account are astronomically long, Mr. Herley explained in a conversation last month.

Mr. Herley said the proposed system hadn’t been tested and that users might become frustrated in trying to select a password that was no longer available. But he said he believed an anything-is-permitted password system would be welcomed by users sick of being told, “Eat your broccoli; a strong password is good for security.”

Saturday, August 14, 2010

Google looks out to include Paypal payments for Android Apps

If you want to pick up a new app on an Android-based smartphone, you have one option with which to pay for your new purchase: Google Checkout. At least, for now—sources indicate that Google is chatting with eBay's PayPal business to bring the latter as a secondary option for smartphone-based payments.

While that doesn't necessarily help the speed of the transaction—Google Checkout is, after all, is still a fairly convenient method for purchasing applications—it does help Google attract users who, for whatever reason, have simply opted not to use Google's single payment service for their purchases.

Integrating Paypal would open up Android phones to the service's 87 million active accounts, which would surely go a long way toward increasing the propensity of a user to pick up a new application on a whim—especially if the Paypal service is integrated into the mobile operating system in a similar style to how purchases work on Apple's App Store.

"As an Android user, I'd certainly be more inclined to buy apps from the Android Market if PayPal was a payment option," writes Intomobile's Marc Flores. "Make it a one-click feature and perhaps I'll even go nuts loading my EVO 4G with new applications."

Neither Paypal nor Google are discussing the alleged talks, which may or may not lead to a finalized deal between the two companies, reports Bloomberg.

According to the research firm Gartner, Google's Android operating system is now the most popular piece of smartphone software in the United States. Sales of Android-based devices rank third of any smartphone in the world in 2010 thus far, nestled behind RIM and Symbian's respective sales of 11.2 million and 22.3 million units. Apple's iPhone sales rank fourth at 8.7 million, or a market share of 14.2 percent to Android's 17.2 percent.

It's quite a turnaround from this same time period one year ago, when Apple commanded 13 percent of the market to Android's 1.8, and Symbian carried the majority market share at 51 percent. Microsoft's Windows mobile phones continue to lag with only 3 million units sold in 2010, a market share of a paltry 5 percent (itself, a decrease from 2009's 9.3 percent)

I think that if such a move is true from Google's side, it could make the Android a popular one!

Wednesday, July 29, 2009

Google opens Checkout for all websites: Now Online Shoping Made Easy!!!

Google has added a new widget into its Labs library that makes opening up your very own online store incredibly easy.

Users simply have to sign up for Google Checkout merchant account, put the details of what they want to sell in a spreadsheet, and then choose from a range of widgets to embed in their site.

Google is offering tiny, small and large widgets to display your stuff, which essentially takes the hassle out of selling stuff online by letting you have your own little shop.

Size options

You can embed the gadget in a variety of ways, with it being easiest in Google branded sites (ie Blogger or iGoogle) but also any site built using HTML (which is fairly wide ranging...)

Google states that using this method means "a fast, secure checkout process [that] helps Google Checkout users convert 40% more than shoppers who have not used Checkout before."

It's subject to Google's transaction fees of course, which if you sell less than £1500-worth of stuff a month you'll incur 3.4 per cent of the fee plus 20p for each thing you sell (with the costs coming down the more stuff you shift).

If you're a wannabe entrepreneur, a web lover but too lazy to actually set up an online presence, then head on over to http://storegadget.googlelabs.com/ and get creating.

Thursday, March 12, 2009

How to Protect Your PC

Use anti-virus software and keep it up-to-date

If you haven't installed anti-virus software on your computer, do it now. Anti-virus software can detect many — but not all — forms of malicious software before they have a chance to affect your computer. When you purchase anti-virus software, look for one that includes anti-spyware. Most anti-virus software can automatically download updates for you. Check to make sure your software is downloading updates correctly.

Keep all your software up-to-date

You can prevent many problems by regularly checking for and installing updates for your programs, including your operating system, browser, messaging software, and other software. Many programs include a feature that automatically checks for updates. Be wary of clicking links in emails claiming to have updates for your software; it is safer to type the address of the web site into your browser’s Address bar to visit the site directly.

Check your security settings

Most operating systems (such as Windows XP) have a built-in firewall and other safeguards to prevent unauthorized access to your computer. Check your operating system to make sure it's set up so that your computer is protected. Install any security updates or patches for your operating system promptly.

Be careful opening email attachments

Consider turning off the feature in your email programs that automatically opens attachments. If you receive an attachment you aren't expecting, do not open it. Before you open any email attachment — even if it's from someone you trust — scan it using anti-virus software. Most of the online mail service providers automatically scans all email attachments for viruses.


Don't install unfamiliar programs

Think carefully before installing or running new software, such as freeware or shareware programs available online. Only download software from a source you trust. Do not install software if you cannot verify that it's from a trusted source. Make sure you know what the software will do and how it will affect your computer. Malicious software (like viruses and spyware) often masquerade as legitimate and even useful programs. For example, you might be tempted to download a program that claims to keep your computer clock synchronized with an official clock. But if that program contains adware or spyware, it could also display advertising pop-ups whenever you're online or keep track of where you go on the Internet.

Be wary of pop-up and email warnings

Don't believe every warning you read — especially pop-up warnings that you see while you're surfing the Web. Unscrupulous companies use pop-up ads to display false warnings about your computer. Ignore them.

Do NOT click any button in the pop-up (such as a "Close" or "No" button) or the Close box that may appear in the upper-right corner of the pop-up. Closing a pop-up in that way might actually install a virus or other malicious software on your computer. To close a pop-up ad, press Ctrl-W (if you're using a Windows computer) or Command-W (on a Mac computer). You may receive an email warning that claims to be from a computer "expert" warning you of a virus. These are usually hoaxes. Do not follow the steps described in any email unless you're sure the threat is real.

Saturday, January 17, 2009

Now, a credit card that cannot be stolen!

Your online shopping just got easier and safer with the virtual credit card. But, what's a virtual card? A virtual card is just like your credit/debit card; only it isn't tangible. It was introduced to check the rising instance of fraudulent transactions over the Internet.

How does it work?

Many banks offer this facility but the process works differently with different banks. However, here’s a general outline:
Let's assume you have a bank account with ABC Bank. Now, follow these steps to get your very own card.
Step 1: Log on to your online account
Step 2: Register for the use of this virtual card
Step 3: Fill in the amount you will need for shopping
Step 4: The bank will generate an exclusive 16 digit number, a CVV2 number and expiry date for this virtual card
There you go, you are ready for shopping online. However, the card will be valid only for a particular period of time; usually, it’s valid for 24 hours. So, you need to use it within that time frame. It can be used at any merchant website, which accepts the service provider (VISA, Master card) mentioned in the card.
Features of a virtual card:

1. It is a safe and risk-free option
2. It has temporary PIN numbers, which assures safety
3. It is time bound; one needs to use it within the time limit specified before the virtual card expires
4. You need to set a limit to your spending and will be eligible to avail the amount specified on the card, which is dependent on the credit limit of your credit card or cash reserves on your debit card.
5. You can use both your credit card and debit card to generate your virtual card!
6. The balance amount, if any, will be credited back to the main account.
There are a few disadvantages: There could be delay in shipping merchandise, as the merchants might wait to receive the money before dispatch of goods.
Also, you need to complete a transaction within 24 hours. So, forget about paying at your leisure. Once a transaction has been completed successfully, the card cannot be used a second time. There is also a spending limit of Rs 50,000 with most banks that you need to keep in mind.
Cost
Most banks provide the use of a virtual card for free. You only need to be registered with online banking, and you can generate several virtual cards in a day.

Search The Fire Seal

Random Post: I'm feeling lucky!!!