ECommerce Security Issues

1 / 9
About This Presentation
Title:

ECommerce Security Issues

Description:

The bank supplied a telemarketer (MemberWorks) with sensitive ... Wells Fargo, Bank of America decided to not continue this practice after the settlement. ... – PowerPoint PPT presentation

Number of Views:137
Avg rating:3.0/5.0
Slides: 10
Provided by: informat546

less

Transcript and Presenter's Notes

Title: ECommerce Security Issues


1
E-Commerce Security Issues
  • Randy Marchany
  • VA Tech Computing Center
  • Blacksburg, VA 24060
  • Marchany_at_vt.edu
  • 540-231-9523

2
Whats Different?
  • The security issues that deal with mail-order
    business are the same that deal with the
    Internet.
  • Security weaknesses in the postal system Vs.
    security weaknesses on the Net.
  • The vulnerable spots are at the endpoints.
  • The customers computer
  • The business computers

3
Dont Abuse Your Customers Privacy
  • The govt. isnt the biggest threat to our
    privacy. Businesses are.
  • US BankCorp was sued for deceptive practices in
    1999.
  • The bank supplied a telemarketer (MemberWorks)
    with sensitive customer data such as name, phone
    , bank acct and credit card , SSN, acct
    balances and credit limits

4
Dont Abuse Your Customers Privacy
  • MemberWorks used these customer lists to sell
    dental plans, videogames, services.
  • US Bancorp settled out of court.
  • Wells Fargo, Bank of America decided to not
    continue this practice after the settlement. Many
    banks still deal with MemberWorks today.

5
Privacy Issues
  • Customers were told in writing that personal info
    is confidential. Duh!
  • No federal law shields transaction and
    experience info.
  • SSN are for sale by Private Firms.
  • Self-regulation doesnt work.
  • The next frontier will be the data held by
    states. DMV...

6
Ensuring E-Trust
  • Do NOT misuse customer data or your business will
    suffer. Word spreads fast!
  • Internet business success requires an alliance
    between business and tech groups.
  • Must be a MAJOR alliance between IT and financial
    audit/control function.
  • You must TRAIN your staff in security related
    issues.

7
Ensuring E-Trust
  • Two threats to customer safety and confidence in
    e-commerce.
  • Coordinated attack on Yahoo, eBay, ZDNet, Buy.com
    (IPO day), amazon.com generated huge amounts of
    publicity.
  • DoubleClick and other firms that collect customer
    info and route it to other firms are able to
    associate any transaction with a person.
  • Personal Service Vs. privacy and anonymity

8
Conclusions
  • Internal threats are more likely.
  • Good training prevents 99 of attacks.
  • IT and financial control and audit alliance is
    critical to building customer confidence.
  • Risk that and every element of your online
    business strategy is at risk.

9
References
  • Training
  • www.sans.org
  • www.nipc.gov
  • Articles
  • Ensuring E-Trust by Peter Keen, ComputerWorld,
    3/13/00 issue
  • The Spies in Your Pocket by Jane Bryant Quinn,
    Newsweek, 8/16/99
Write a Comment
User Comments (0)