Title: ECommerce Security Issues
1E-Commerce Security Issues
- Randy Marchany
- VA Tech Computing Center
- Blacksburg, VA 24060
- Marchany_at_vt.edu
- 540-231-9523
2Whats Different?
- The security issues that deal with mail-order
business are the same that deal with the
Internet. - Security weaknesses in the postal system Vs.
security weaknesses on the Net. - The vulnerable spots are at the endpoints.
- The customers computer
- The business computers
3Dont Abuse Your Customers Privacy
- The govt. isnt the biggest threat to our
privacy. Businesses are. - US BankCorp was sued for deceptive practices in
1999. - The bank supplied a telemarketer (MemberWorks)
with sensitive customer data such as name, phone
, bank acct and credit card , SSN, acct
balances and credit limits
4Dont Abuse Your Customers Privacy
- MemberWorks used these customer lists to sell
dental plans, videogames, services. - US Bancorp settled out of court.
- Wells Fargo, Bank of America decided to not
continue this practice after the settlement. Many
banks still deal with MemberWorks today.
5Privacy Issues
- Customers were told in writing that personal info
is confidential. Duh! - No federal law shields transaction and
experience info. - SSN are for sale by Private Firms.
- Self-regulation doesnt work.
- The next frontier will be the data held by
states. DMV...
6Ensuring E-Trust
- Do NOT misuse customer data or your business will
suffer. Word spreads fast! - Internet business success requires an alliance
between business and tech groups. - Must be a MAJOR alliance between IT and financial
audit/control function. - You must TRAIN your staff in security related
issues.
7Ensuring E-Trust
- Two threats to customer safety and confidence in
e-commerce. - Coordinated attack on Yahoo, eBay, ZDNet, Buy.com
(IPO day), amazon.com generated huge amounts of
publicity. - DoubleClick and other firms that collect customer
info and route it to other firms are able to
associate any transaction with a person. - Personal Service Vs. privacy and anonymity
8Conclusions
- Internal threats are more likely.
- Good training prevents 99 of attacks.
- IT and financial control and audit alliance is
critical to building customer confidence. - Risk that and every element of your online
business strategy is at risk.
9References
- Training
- www.sans.org
- www.nipc.gov
- Articles
- Ensuring E-Trust by Peter Keen, ComputerWorld,
3/13/00 issue - The Spies in Your Pocket by Jane Bryant Quinn,
Newsweek, 8/16/99