1. 30
Lies About Secure Electronic Commerce: The
Truth Exposed
"You are likely to hear all sorts of things
about secure electronic commerce these days,
and I figured you might want to know what
kind of assertions with limited veracity
value are out there." From Fred Cohen &
Associates, security consultants.
|
2. CNET
News.com: Microsoft, VeriSign Team on
E-Commerce Security
"Microsoft, VeriSign and WebMethods said
they have developed technology (the XML key
management specification -- XKMS) designed
to make it easier to use digital signatures
and other online security tools with
e-commerce applications." (11/29/00)
|
3. Electronic
Commerce Interest Group
The World Wide Web Consortium presents a
collection of documents concerning
e-commerce security.
|
4. Forbes.com:
Amex's Private Payments Aimed More at Fears
Than Reality
"Private Payments, a new program that
assigns shoppers a unique number that may be
used for online purchases and expires
immediately after the transaction is
completed" is American Express's attempt to
assuage fears about online security.
(9/8/00)
|
5. Gartner:
Secure Your Customers
"The Internet has become a hugely powerful
force for enterprises, both public and
private. But just as it has gained strength,
it has also acquired an Achilles' Heel."
Research, commentary, advice.
|
6. Information
Systems Audit and Control Association:
E-commerce Security: Components Which Make
it Safe
"The critical components of communication
security comprise cryptography, digital
certificates and certification authorities.
Let us look the components in detail and
determine how these components address the
risks concerning e-commerce." (8/00)
|
7. InfoWorld:
Visa Sets Guidelines for Safe Transactions,
Forces Security on (Willing?) Merchants
"These (Visa Account Information Security
Standards) seem like a great start, but the
skeptic in us asks, 'Who will make sure
these very generic criteria are met at the
technical level, and what are the
consequences of noncompliance?'" (10/20/00)
|
8. Newsbytes:
Security Breaches Cost $15 Bil Yearly -
Datamonitor
"The more businesses rely on the Internet,
the more fraud and security breaches occur,
according to an e-security white paper and
allied report, 'E-security: Removing The
Roadblock to E-business,' issued by the
Datamonitor group." (11/15/00)
|
9. NIST
Computer Security Resource Clearinghouse
Designed to collect and disseminate computer
security information and resources to help
users, systems administrators, managers, and
security professionals better protect their
data and systems.
|
10. Safeshopping.com
Informational site for consumers by the
American Bar Association which covers
security, privacy, payment issues, product
evaluation, shopping/return/refund policies,
delivery terms, where to file complaints,
and other tips.
|
11. SANS
Alerts: Large Criminal Hacker Attack on
Windows NTE-Banking and E-Commerce Sites
"In the largest criminal Internet attack to
date, a group of Eastern European hackers
has spent a year...exploiting...Windows NT
vulnerabilities to steal customer data." A
million-plus credit cards have been taken,
40+ sites have been victimized. (3/8/01)
|
12. Slashdot:
Caveat Emptor: Egghead.com Credit Records
Nabbed
"Wish these big companies would learn...
It's too bad this kind of theft will
probably scare people away from online
purchases even when it's a database that's
cracked rather than their transactions."
Discussion of credit card security
(12/22/00)
|
13. Trust
and Risk in Internet Commerce
"Trust is the critical variable in Internet
Commerce. Trust requirements differentiate
Internet from other forms of commerce. Trust
has three primary components: reliability,
security, and privacy." This online textbook
discusses all three in depth.
|
14. VeriSign:
Guide to Securing Your Web Site For Business
This guide explains key issues related to
Web security, describes the technologies
VeriSign uses to address the issues, and
provides step-by-step instructions for
obtaining and installing a VeriSign Server
ID.
|
15. Visa
USA Cardholder Information Security Program
Top ten list of best practices for all
"card-not-present" merchants and their
agents that process or store cardholder data
and have access to that information as a
result of mail/telephone or Internet
acceptance of Visa account information.
|