Subscribe:

Tuesday, 13 December 2011

SSL Certificate and Cyber Security

This article provides plenty of information about Cyber Security and usefulness of SSL certificates to protect your ecommerce website. Know about how to protect Cyber Security & Online transaction(payment) with SSL Certificates.

Since last 20 to 25 years world is rapidly changed to cyber world. Cyber made all things fast and closest. Living miles away, people can see, speak, and live as sitting on coffee table. Cyber innovation changed the growth of world beyond imagination in last 25 years. When a computer was invented it was a giant and now people use it as notebook. Technology is developing rapidly with unmeasured growth.

A rapid growth of cyber required security and safety. People started talking online, shopping online, banking online even getting married online. Let’s talk about cyber security, many online shoppers, sellers and bankers were abused by Hackers (Kind of thieves). These thieves were major problem on cyber invention. People started feeling unsecure started avoiding online dealings. Innovation is on growth and did not want to stop or running back to zero. Technology gurus found key to secure online data and this key is SSL certificate.

What are hackers and hacking?

Hackers are thieves who try to gain un-authorized access to your computer via network or program. Stealing data from computer or network is called hacking. Like as thieves Hackers do not knock your door. They get un-authorized access and start stealing your personal data. You realize once see loose of data, money and everything

Who invented SSL certificate?

SSL certificates are developed on protocol SSL (Secure Socket Layer) by Netscape in 1994. Netscape used encryption and decryption technology to make data unreadable for hackers. Incase hackers steal encrypted data then even he can not read get correct data.

Later technology established SSL certificate standards and authorized few organizations to work as SSL certificate issuer. They are called SSL CA – Certificate Authorities. Few of them are VeriSign, GeoTrust, Thawte, Equifax, Entrust, Global Sign, RapidSSL, Comodo. All these CAs are authorized for issuing Web Trust certificates. SSL technology started supporting up to 256 bit encryption to secure online data.

Conclusion:

As online shopper, seller or banker trust only SSL certificate website. Real merchants always used SSL certificate securing customer credit card details and private information. Do not get abused with good web designs and words, as scammers always use such scamming ideas. Trust only ssl certificate secured websites.
To know more about Different types of SSL Security Certificate visit  https://www.thesslstore.com/

Source: cybernewsnetwork

Friday, 9 December 2011

Skype Security Flaw

The researchers found several properties of Skype that can track not only users' locations over time, but also their peer-to-peer (P2P) file-sharing activity, according to a summary of the findings on the NYU-Poly web site. Earlier this year, a German researcher found a cross-site scripting flaw in Skype that could allow someone to change an account password without the user's consent.

"Even when a user blocks callers or connects from behind a Network Address Translation (NAT) ­-- a common type of firewall ­-- it does not prevent the privacy risk," according to a release from NYU-Poly.

The research team tracked the Skype accounts of about 20 volunteers as well as 10,000 random users over a two-week period and found that callers using VoIP systems can obtain the IP address of another user when establishing a call with that person. The caller can then use commercial geo-IP mapping services to determine the other user's location and Internet Service Provider (ISP).

The user can also initiate a Skype call, block some packets and quickly terminate the call to obtain an unsuspecting person's IP address without alerting them with ringing or pop-up windows. Users do not need to be on a contact list, and it can be done even when a user explicitly configures Skype to block calls from non-contacts.

This has always made me wonder why these programs have their own security policies. Can't it be possible for products such as skype, which millions of people use to connect to friends and family globaly, to work with dedicated secuirty software to stop any unwanted threats. For instance, both Xbox Live and the Playstation online network have been hit by fraudsters this year and stolen millions from unsuspecting users. So wouldn't working together be benificial for all parties, if the technology is already there why develop your own inferior product?

For more Information about security certificates visit https://www.thesslstore.com/

Source: symantec

Monday, 21 November 2011

Keep in mind of Your Vacation Take a trip E-Ticket Confirmation


How does Symantec know it's the week of Thanksgiving? Because as the most popular travel day of the year day quickly strategies, the day just before Christmas, there is an increase in bogus mail solution confirmations that lead to infections.

Here is what bogus air travel information looks like:




 If you examine the HTML development for this information properly, you will see a destructive weblink in the core tag:

This weblink markets to a known malware-hosting site in Italy which in the past put Virus.Maljava. Virus.Maljava is a recognition name used by Symantec to recognize destructive Coffee information that uses one or more weaknesses, one of many risks looking forward to an trusting person.

So before you click through messages during the trip hurry, here are some best methods to secure yourself from these types of destructive mail attacks:

    * Be particular about sites you give your mail to.
    * Before coming into personal or financial information online, ensure the website has SSL security (look for things like HTTPS, a 'lock', or a natural deal with bar).
    * Avoid hitting dubious links in mail or information as these may be links to spoofed sites. We recommend writing Web covers immediately into the technique rather than based upon links within your information.
    * Do not start trash information
    * Do not respond to trash. Generally the sender’s mail is cast, and responding may only result in more trash.
    * Do not start unfamiliar mail emotions. These emotions could give up your computer.
    * Always be sure that your os is up-to-date with the newest messages and use a complete security selection. For information on SSL Certificates choices, visit http://www.thesslstore.com

source: symantec

Wednesday, 2 November 2011

Google to offer free websites to Indian businesses

Google Inc said it will offer free websites to small and medium businesses in India in a move to boost Internet usage in Asia's third-largest economy and aims to get half a million of these businesses online in the next three years.

India is the world's second-biggest mobile phone market with about 870 million users, but Internet penetration is low. About 100 million, or less than a tenth of a country of 1.2 billion people, use Internet although that still makes it the world's third-biggest Internet user market.

The country is home to an estimated 8 million small and medium businesses, of which about 400,000 have a website and 100,000 have active online presence, Google said in a presentation on Wednesday.

The online commerce, or e-commerce, market in India is small now but few people doubt one day it will be a big business in the country. Google said in the presentation e-commerce in India has hit an "inflection point."
"We want to build an ecosystem...We are investing in the market," Nikesh Arora, Google's chief business officer, told reporters in Delhi, adding the country was not a big revenue market yet but a good user market.
Rajan Anandan, managing director of Google's Indian unit, said the Internet search giant was making "significant" investments in the free web hosting initiative but had no "near-term revenue expectations" from it.

Google and its partner web hosting firm HostGator will facilitate free web domain names and will maintain the websites for a year without charging any fee. At the end of the first year, users will have to pay a "nominal charge" if they wish to renew their domain name, Google said in a statement.

source:moneycontrol

Sunday, 25 September 2011

Lync Deskphones and Wildcard Certificates


A critical component of any Lync deployment is the deskphone.  While some users may be comfortable with using a headset/PC combo as their primary telephony interface, I've found that most users still prefer a deskphone.

However, getting a Lync deskphone to work with Lync can be a bit tricky if you aren't diligent about following Microsoft best-practices to the letter.  You may have a Lync environment that works perfectly well for computer-based Lync clients, but you may come across various connectivity issues when you plug in a Lync deskphone that does presence and Exchange calendaring. 

I recently came across a client who were having Exchange connectivity issues with their Polycom CX600 phones.  The Polycom CX600 is likely the most popular Lync deskphone. It provides a very slick interface into Lync and Exchange so you can see your presence, contacts and upcoming meeting information. It is also very cost-effective compared to other similar products.

When users signed into Lync on their CX600 (either via keypad or USB-PC integration), they were soon presented with the following error:
 
Microsoft Exchange integration unavailable.  Connection to Exchange is unavailable due to invalid network credentials.
The CX600 uses Exchange Web Services (EWS) and autodiscover to find the connection to Exchange.  If there are issues with either service, it will pretty much guarantee that the CX600 won't connect.  I verified that both EWS and autodiscover were working properly.

When I reviewed the certificate loaded on the Exchange Client Access Server, I saw that the common name (CN) was set to their public domain (ie. contoso.com).  The Subject Alternate Names (SAN) included all the required names.  Microsoft Lync documentation recommends that you do not use certificates with the CN set to a wildcard domain name.  You CAN use wildcards in the SAN, but the CN really should be a valid name.  In this case contoso.com is the same as *.contoso.com. 

The client replaced the certificate with one whose CN matched the externally accessible name of the CAS server (owa.contoso.com) as reported by Exchange.  They issued an IISReset, restarted the CX600 and the error went away.  They now have full connectivity to Exchange via the CX600.

I've seen variations on this many times on both Exchange and Lync.  If you're only using Lync PC clients, you may never notice any issues, but as soon as you bring deskphones and even mobile phones into the mix, these sort of things often come up. 

So as a general rule, if you're creating certificates for Lync or Exchange, 
DON'T use a Wildcard SSL as the first name.

The Symantec® NetSure® Protection Plan, the Best in the Biz


Yet another hands down reason to choose a Symantec® SSL product over the other guys. Symantec® now offers an incomparable NetSure® Protection Plan with each and every Secured Sockets Layer (SSL) certificate. The NetSure® Protection Plan is an extended warranty program that keeps its customers and their companies first. It protects SSL Certificate customers against certain losses that possibly resulted from a breach on Symantec®.

This one-of-a-kind warranty extension applies to the VeriSign®, Thawte® & GeoTrust® brands and is just another distinct advantage over the competition.

VeriSign SSL Certificates now include up to a whopping $1,500,000 of NetSure® protection…just to give you a peace of mind and to show you that they truly believe that they are the best security company out there. They truly put their money where their mouth is.

The True Symantec® Advantage

This dramatic increase in warranty coverage across all of the different Symantec® SSL products is a true testament to their confidence in their products and provides VeriSign®, Thawte®, and GeoTrust® customers with the level of trust and security they have come to expect only from Symantec® and The SSL Store.


The New Warranty Limits
The new warranty limits for NetSure® protected SSL certificates are as follows and coverage applies to the following certificates issued on or after 
July 30th, 2011:




VeriSign Trust Network Certificates


SECURE SITE WITH EXTENDED VALIDATION
SECURE SITE PRO WITH EXTENDED VALIDATION

USD $1,500,000

SECURE SITE PRO CERTIFICATE

USD $1,250,000

SECURE SITE CERTIFICATE

USD $1,000,000

WILDCARD SSL CERTIFICATE

USD $500,000

ANY VERISIGN TRUST NETWORK CERTIFICATE SUBJECT TO THE LICENSED CERTIFICATE OPTION

USD $10,000

**CODE SIGNING CERTIFICATES ISSUED PURSUANT TO CODE SIGNING 
PORTAL ACCOUNTS ARE NOT CONSIDERED NETSURE CERTIFICATES

USD $0



Thawte Certificates


THAWTE SSL WEB SERVER CERTIFICATE WITH EXTENDED VALIDATION

USD $750,000

THAWTE SGC SUPERCERT

USD $500,000

THAWTE SSL WEB SERVER CERTIFICATE

USD $250,000

THAWTE WILDCARD SSL CERTIFICATE

USD $125,000

THAWTE SSL123 CERTIFICATE

USD $100,000

THAWTE CODE SIGNING CERTIFICATE

USD $50,000



Geotrust Certificates


GEOTRUST TRUE BUSINESSID WITH EXTENDED VALIDATION

USD $500,000

GEOTRUST TRUE BUSINESSID
GEOTRUST ENTERPRISE SSL STANDARD CERTIFICATE
GEOTRUST ENTERPRISE SSL PREMIUM CERTIFICATE

USD $250,000

GEOTRUST TRUE BUSINESSID WILDCARD
GEOTRUST ENTERPRISE SSL WILDCARD CERTIFICATE

USD $250,000

GEOTRUST TRUE BUSINESSID WILDCARD
GEOTRUST ENTERPRISE SSL WILDCARD CERTIFICATE

USD $125,000

GEOTRUST QUICK SSL PREMIUM CERTIFICATE

USD $100,000

CERTIFICATES ISSUED PURSUANT TO GEOROOT ACCOUNTS ARE NOT 
CONSIDERED NETSURE CERTIFICATES

USD $0



RapidSSL Certificates


RAPIDSSL CERTIFICATE

USD $10,000

RAPIDSSL ENTEPRISE CERTIFICATE

USD $10,000

RAPIDSSL WILDCARD SSL CERTIFICATE

USD $5,000

Please contact us for more information on the NetSure® Extended Warranty Protection Plan.

Source URL:-https://www.thesslstore.com/support/symantec-netsure-protection-plan.aspx