Ipinapakita ang mga post na may etiketa na website protection. Ipakita ang lahat ng mga post
Ipinapakita ang mga post na may etiketa na website protection. Ipakita ang lahat ng mga post

Huwebes, Mayo 2, 2013

Explaining PCI Compliant Website Security Scans



Best business practices, especially when it comes to online safety and security, is something all business owners should consider – regardless of the size of their companies or the amount (if any) of online sales.
With an average of 5,000 new vulnerabilities discovered each year, regular or continuous vulnerability scanning is an essential security best practice.Recent studies show that over 70% of security threats are directed at web applications due to the quantity and value of the information they contain, a problem that's particularly acute for online merchants.
PCI Security Standards CouncilPCI stands for the Payment Card Industry. The main credit card companies all got together and organized a Security Standards Council which in turn created a data security standard. They require that all online merchants be compliant with their standards. PCI compliant security scans check to determine whether or not these web applications spoken of earlier have vulnerabilities. It checks for other possible places where clients or websites could be compromised by a virus or hacker.
Trusted website security companies like Trust Guard provide a report after scanning the server or website. The report gives business owners and/or their IT support staff the information they need to repair the vulnerabilities, if any. When businesses scan their site daily, there is a significantly lower chance that hackers or viruses will infiltrate their website and servers.
Every business that accepts and stores credit card data must demonstrate compliance with PCI DSS, but the complexities of securing business networks present considerable challenges, especially for smaller businesses with limited IT resources. However, security scanning packages can be obtained for a reasonable fee. In fact, Scanning companies that offer security seals for scanned businesses to display on their websites will find that sales will increase and conversion rates will improve. This is because online consumer trust scanned sites more than they trust non-scanned sites – as well they should.
The PCI Scan Service requires no hardware or software to be installed and managed. Inserting a small snippet of code on the website page is all that is required to both scan the site and display the trust seal and accompanying certificate. The seal and certificate demonstrates the business’ commitment to keep their site safe for themselves and their customers.
For additional questions about PCI Compliant Website Security Scans, visit Trust Guard today.

Miyerkules, Mayo 1, 2013

Six out of Ten Belgians Faced Online Safety Issues in 2012



According to a research study, only half of the Belgians polled are worried or extremely worried about their online safety. My question is why are only half of them worried?
Cert.be, the Belgium Federal Cyber Emergency Team’s website recently commissioned a study on Internet safety amongst 2,000 Belgian Internet users aged between 16 and 70 years. The results show that 6 out of 10 Belgians had been confronted with online safety issues in 2012.

Cybercrime has been mentioned time and time again in the media in recent months. Typically the reports involve companies or organizations that are targeted by cyber criminals. Why is it that everyday online consumers and small online business owners – although they acknowledge that other individuals and entities just like them have had security breaches – aren’t afraid enough of the threat to start protecting themselves and their websites from hackers and identity thieves?

Interestingly enough, the CERT.be study shows that increasingly, end users are facing various security problems more often than ever. Here’s how the data looks based on the study:

Security and Safety Threat                                        Percent of Users Affected by the Threat      
Viruses or malware that directly harm the computer                            25.72%
Malicious attempts to steal money or information                               18.56%
The sending of unwanted e-mails from one’s own address                 17.16%
Passwords that suddenly stop working                                                 14.03%

Almost half of the Internet users in Belgium (49.15%) are highly to very highly concerned about their online security. A third (34.78%) appear to be neutral, while 16.07% said that they had no anxieties at all. The greatest anxieties relate to Internet banking (where 60.75% are worried) and online shopping (46.17%).

It is no coincidence that these are two activities where money directly changes hands. More than a third of the Belgians immediately become cautious when surfing to unknown sites (35.12%) or when receiving requests for personal information (34.73%). Social networking has a quarter of Belgians concerned, while surfing on a public wireless network seems to cause only 14.98% of Belgians any anxieties.

The concern however is not immediately reflected in behavior, as preventative measures, like online business owners scanning their sites for vulnerabilities, have not increased significantly. For example, 40% of the Belgians researched only change their passwords in case of problems or if they have forgotten their passwords. Twenty-two percent of the participants never change their passwords unless they are required to do so.

Christian Van Heurck, coordinator of CERT.be, states that "Cybercrime is increasingly becoming a reality for end users as well. It's no longer just about viruses and malware, but also increasingly about attempts to steal personal information or to misuse financial accounts. It is true that people are worried, but they often fail to assess the risks correctly, and often do not know how to optimally protect themselves.

“For this reason, we are currently working hard on developing a central website where end users can find objective information concerning Internet threats and will also receive tips on how to better protect themselves. The aforesaid results clearly show that there is need for it. "

Like waiting to brush your teeth until the dentist pulls them out, online consumers and business owners often wait until their identity has been stolen or their website has been hacked before doing anything to remedy the situation.

Lunes, Abril 22, 2013

Prison Personnel Lets Super Hacker Use Their Computer



Guess what happens next. 

Before we tell you, let’s give you a little background. Before he was arrested in 2011, Nicholas Webber described himself as the world's "most wanted cybercriminal." At the tender age of seventeen, he created the site GhostMarket, where he gave tips on harvesting credit card data and writing computer viruses.

But that’s not all; he also provided a clearinghouse for hundreds of thousands of stolen credit cards. Webber used stolen financial data to buy high-end electronics and reserve rooms in luxury hotels, including a penthouse at London's Park Lane Hilton.

This infamous British hacker, who was responsible for as much as $22 million in financial fraud before going to prison,hacked into his its computer system after he was allowed to use a computer while attending an IT class.

Needless to say, Webber didn't need any lessons in information technology. It is a mystery as to why the prison allowed him to take a class and access a computer in the first place. They either didn’t know about his past crimes or didn’t care. Let’s give the prison workers the benefit of the doubt and say that he gained access to the class by bribing another inmate who looked like him and then wore sunglasses and a hoodie to disguise himself. 

Although the incident took place in 2011, it has come to light now because the worker whom the prison blamed for the hack—and who was subsequently fired—is suing his former employer. Michael Fox (wait, is that his real name or is this yet another case of identity theft?) claims he had no idea Webber was a hacker when he allowed him into the class.
Officials continue to assert that Webber did not access private data. But according to The Daily Mail, the hack caused "major panic" at the prison, and issues began happening that had not happened previously.

HM Isis, the brand-new, $150 million facility where Webber is imprisoned, has been "bedeviled" by a series of technological breakdowns, most related to its state-of-the-art biometric system, where prisoners must swipe their fingerprints to move from one section of the prison to another. According to an inspection last January, the system broke down once every day for five days. We're sure Webber had nothing to do with it.

Many online business owners are just as naïve as this prison worker – allowing vulnerabilities to exist on their websites and servers without ever scanning to see what they are so that they can remove them – simply because they erroneously believe that everyone should worry about hackers except them.

Sabado, Abril 20, 2013

The Growing Threat of Cyber Crime



Among the topics most discussed by Director of National Intelligence James Clapper during the Senate Intelligence Committee hearing on ‘Current and Projected National Security Threat to the United States,” Clapper confessed that the U.S. economy is vulnerable to relatively unsophisticated cyber attacks

Yes, Iran is making progress toward developing nuclear weapons. Yes, Al Qaeda sympathizers are resurging across North Africa and the Middle East. But the danger of online attacks to the United States’ crucial infrastructure by enemy hackers is also a significant concern to the country’s security and even tops the other two considerable issues.

As a result, America’s intelligence agencies are reevaluating how they operate.“Threats are more diverse, interconnected and viral than at any time in history. Attacks, which might involve cyber and financial weapons, can be deniable and unattributable,” he says. 

“Foreign intelligence and security services have penetrated numerous computer networks of U.S. government, business, academic and private sector entities…. This is almost certainly allowing our adversaries to close the technological gap between our respective militaries, slowly neutralizing one of our key advantages in the international arena.”

Although his 34-page statement listed cyber-threats as first among global perils, he says the likelihood of a major computer-driven attack over the next two years is remote. Russia and China, the two most capable nations, “are unlikely to launch such a devastating attack against the United States outside of a military conflict or crisis that they believe threatens their vital interests.”

But he warns that “isolated state or non-state actors might deploy less sophisticated cyber-attacks as a form of retaliation or provocation. These less advanced but highly motivated actors could access some poorly protected U.S. networks that control core functions, such as power generation.”

It’s interesting to think about the 30 minute power outage at this year’s NFL Super Bowl and not at least consider that an enemy to the United States might have hacked into the online platform that supported the electrical system. 

Even if the attacks start small, the damage could spread because networks are so inter-connected.Cyber-espionage is rampant and growing. Business owners and companies loyal to the United States of America should seriously consider securing their online portals with SSL certificates, business verification tools and daily payment-card-industry compliant website and server security scans for vulnerabilities used by hackers unfriendly to the US to access personal 
and financial data.