{
    "success": true,
    "data": {
        "id": 1352944,
        "msgid": "bichecked-by-richbi-1447899208",
        "date": "2003-05-11 00:00:00",
        "title": "checked by Rich ",
        "author": null,
        "source": "JP",
        "tags": null,
        "topic": null,
        "summary": "checked by Rich Indonesia lagging behind world in internet security Wasis Gunarto Contributor Jakarta Talking about internet banking leads us to the security aspects. The subject becomes more urgent as, in terms of security for banking transactions via the Internet, Indonesia is now ranked number two from the bottom, only better than the Ukraine, in cyberfraud.",
        "content": "<p>checked by Rich<\/p>\n<p>Indonesia lagging behind world in internet security<\/p>\n<p>Wasis Gunarto<br>\nContributor<br>\nJakarta<\/p>\n<p>Talking about internet banking leads us to the security <br>\naspects. The subject becomes more urgent as, in terms of security <br>\nfor banking transactions via the Internet, Indonesia is now <br>\nranked number two from the bottom, only better than the Ukraine, <br>\nin cyberfraud.<\/p>\n<p>A survey conducted by ClearCommerce Corporation (a company <br>\nthat provides solutions for real-time Internet transaction <br>\nprocessing, tracking and reporting) also indicated that about 20 <br>\npercent of internet banking transactions originated from <br>\ncyberfraud.<\/p>\n<p>In its survey last year, CastleAsia (a company that <br>\nspecializes in business information and feasibility studies) <br>\nreported that approximately only 15 percent of middle- and small-<br>\nsized businesses in Indonesia were willing to use internet <br>\nbanking, as a large portion were worried about its security.<\/p>\n<p>The saddest part is if most businesspeople do not trust online <br>\ntransactions, the country&apos;s economy will eventually be affected.<\/p>\n<p>However, business activities have to continue in spite of this <br>\n&quot;loophole&quot; and illegal entries into websites by ruthless <br>\ncrackers. Just like a house with locked doors and windows plus <br>\nthe state-of-the-art security devices, the possibility of thieves <br>\nto outsmart them still exists.<\/p>\n<p>For transactions at the personal or individual level, security <br>\nis also problematic, as viruses and trojan horses can break into <br>\nalmost anyone&apos;s computer and the user&apos;s data -- Personal <br>\nIdentification (PIN) and Credit Card numbers etc. -- can be <br>\neasily stolen.<\/p>\n<p>One of my friends, during his college days, boasted about his <br>\nability to find out the e-mail passwords of other students. <br>\nHolding the print-out of the passwords, he explained how easy it <br>\nwas. &quot;Just place a special recording device close to a computer, <br>\ncleverly hidden, of course, like I did in the campus, sit in the <br>\nback row and monitor my victims&apos; data,&quot; he proudly added.<\/p>\n<p>This type of intruder exists everywhere and the number is <br>\ngrowing. With various sophisticated gadgets available on the <br>\nmarket, it is really terrifying how easy such valuable data, <br>\nincluding our hard-earned money, can be snatched away in seconds.<\/p>\n<p>Another enemy is the virus, for example lovebug and sircam. <br>\nThese viruses disrupted computers throughout the world and <br>\ncreated a worldwide panic as vital state secrets and bank data <br>\nhad been plundered. Philip Williams, from the Center of Internet <br>\nSecurity Expertise (CERT), confirmed that two major banks in the <br>\nUnited States and another in Switzerland were the victims of the <br>\nmerciless virus.<\/p>\n<p>All kinds of illegal access, including theft of subscribers&apos; <br>\ndata, can also occur at Internet Service Providers, as, again, a <br>\ncracker can outsmart their security system by using a sniffer <br>\nprogram.<\/p>\n<p>Fake domains can also be created, causing both the bank and <br>\nits customers more than panic or headaches. News about ATM PINs <br>\nthat were forged created further havoc and the lowest sense of <br>\nsecurity for bank customers.<\/p>\n<p>However, advances in security technology, also in leaps and <br>\nbounds, are making it extremely difficult, almost next to <br>\nimpossible, for the bad guys to succeed. Various tools and layers <br>\nof protection are used: spyware, firewalls, Security Socker Layer <br>\n(SSL), public key cryptography and Certificate Authority (CA).<\/p>\n<p>SSL, first developed by Netscape, is like a protective <br>\nwrapping seal on the internet, making it &quot;leakproof&quot; and can only <br>\nbe opened by a special 128 byte combination &quot;key&quot;, which is in <br>\nfact a password known only by the holder and recognized by the <br>\nreceiver or in this case, the bank&apos;s internet system. This <br>\nspecial combination key is usually called public key crytography.<\/p>\n<p>Cryptography was born in the days of the Roman empire. Its <br>\nemperor, Julius Caesar, did not trust his couriers. So, he <br>\nencrypted his messages, for example every letter &apos;A&apos; should be <br>\nread as &apos;D&apos;, &apos;B&apos; as &apos;E&apos; and so forth. Only certain receivers of <br>\nthe messages, with prior knowledge of the special code, could <br>\nread his top secret messages.<\/p>\n<p>In the case of passwords for bank transactions, two kinds are <br>\nused: private keys and public keys. A public key is sent together <br>\nwith encrypted data and if a hacker gets hold of it, the private <br>\nkey, which is, again only known to both the holder and his bank, <br>\nprovides further security.<\/p>\n<p>To assure us of the authenticity of the key or the password, a <br>\ndigital certificate is required. This certificate contains <br>\ninformation that is related to the certificate owner and an <br>\nauthorization statement from a body or institution that <br>\nrecognizes or validates the password user as the authentic <br>\ncertificate owner.<\/p>\n<p>A digital certificate, inserted into a public and private key <br>\nor password, again makes it harder for any forgery.<\/p>\n<p>The most important aspect after all security actions is the <br>\nexistence of a body or institution that can be relied on to <br>\nguarantee, validate and consistently monitor every security <br>\naspect of a transaction via the Internet, including the digital <br>\ncertificates.<\/p>\n<p>This is where the important role of Certificate Authority (CA) <br>\nenters, which is a reputable and trusted body or institution that <br>\nrecords certificates, stores it in its server and authenticates <br>\nthe certificates whenever required.<\/p>\n<p>For banks in Indonesia that provide e-banking, the <br>\nprerequisites are registration and accreditation from an <br>\ninternational Certificate Authority, like Verisign, GlobalSign <br>\nand British Telecommunication, for a more secure and reliable <br>\ninternet banking.<\/p>\n<p>To date, Indonesia has no such institution, although its <br>\nexistence is acknowledged to help reduce the country&apos;s cybercrime <br>\nand enhance its e-commerce.<\/p>\n<p>With the upcoming highly advanced Third Generation (G3) <br>\ncommunication system that will automatically increase mobile <br>\nbanking, the need for a Certificate Authority in Indonesia is <br>\nbecoming ever greater.<\/p>\n<p>Along with that, of course, cyberlaws must come into force to <br>\nprovide consumers with the maximum sense of security for internet <br>\nbanking plus other transactions through the Internet. This way <br>\nrisk management for any company becomes less of a headache.<\/p>\n<p>Tips<\/p>\n<p>Internet banking service has several effective security<br>\ntechniques that we encourage you to implement when you use the<br>\nInternet banking service:<\/p>\n<p>1. Never reveal your password to anyone or leave your password<br>\nanywhere that someone else can obtain and use it.<br>\n2. Change your password on a regular basis.<br>\n3. Use the Exit button to end each Internet banking session. Do<br>\nnot use the Back button to exit the site.<br>\n4. Change your session timeout in User Options to a time that<br>\nmeets your needs.<br>\n5. Balance your account on a regular basis. Internet Banking<br>\nmakes it easy!<\/p>",
        "url": "https:\/\/jawawa.id\/newsitem\/bichecked-by-richbi-1447899208",
        "image": ""
    },
    "sponsor": "Okusi Associates",
    "sponsor_url": "https:\/\/okusiassociates.com"
}