Lost Password? No account yet? Sign up! Why bother?
  • Narrow screen resolution
  • Wide screen resolution
  • Auto width resolution
  • Increase font size
  • Decrease font size
  • Default font size

SmallNetBuilder - Small Network Help

  
Home arrow Security arrow Security Features arrow Ignorance is Bliss? An Introduction to Internet Security - Part 2
Ignorance is Bliss? An Introduction to Internet Security - Part 2 Print E-mail
Pat McKenna   
March 27, 2006

Introduction

Editors Note: the following article is targeted at the common Internet user and attempts to avoid technical jargon as much as possible. Its premise is that administrators and programmers already know the shortcomings of Internet security. This article assumes that the reader has covered the previous article for glossary terms and definitions and does not repeat that material.

To begin with, I want to put you in a frame of mind regarding your security. Simply put, you are fortunate if you avoid ever being attacked through means of your computer. You are less fortunate if you have been attacked, but at least were later informed or otherwise discovered it. In that case you go into damage limitation mode and fix whatever problems have arisen.

But what if you don't realize that you have even been attacked? You cannot 'fix' something that you do not know is wrong. Think of someone using your identity to access information to which they should not have access, and creating accounts in places that you do not know exist, and to which you yourself obviously have no access.

Many people are attacked on the Internet but never realize it. On many occasions, when an institution realizes that customers have been compromised, there are allegations that the attack was kept quiet, and damage likewise repaired silently.

In the previous article, we looked over a range of threats that exist for Internet users. In this article, we are going to delve a bit deeper into how these attacks are mounted. The goal is to help you understand how you are being attacked, so that you can correctly assess your level of security as you transact on the Internet.

The Common Login Page: The Common Security Hole

At the core of our identity management problems is the common login page; its vulnerability has fed a whole generation of hackers. The flaw isn't difficult to understand, either. With usernames and passwords entered either partially or completely, the level of security is weak. Upon successful authentication, the hacker has access to the online facility for the duration of the visit, without hindrance.

This is a key point to understand. A site provides a gateway into its environment, and your username and password details are the key. Once in, there are usually no further identity checks, which means that the only protection to site access - to your email, online banking and so on - is your username and password. In technical speak, we would say that after logging in, session and transaction management are continued until the user logs out, or is otherwise disconnected.

The burning question is why did we (a generation of programmers) ever design and perpetuate a system (the common login box) that we knew to be vulnerable? There are a few reasons: simplicity, complacency and evolution are near the top of the list.

Let's look at the process of attacking systems that depend on login boxes.



Tags: Internet Security,

Related Articles:

They're Out to Get You - An Introduction to Internet Security
Factor Authentication in Online Banking
How To: Fixing DNS problems
How You Are About To Become Responsible For Credit Card Fraud
Privacy Policy
 

Most Read

 
 

Over At The Forums

Any Drobo Review Coming?
Tim last time ( in May?? ) you said you were in queue for Drobo Review unit, Have you have any response from them yet?

Qnap 209 Pro II, very slow transfer, advice welcome
Hello I have a Qnap 209 Pro II, I get a very slow file transfer rate. I think (hope) I have something wrong with either my...

For sale brand new original unlocked BlackBerry Storm 9500 $300
Welcome to Phonesstockcity Ltd in United State, We deal with All Electronics Product it is All Brand New with the complete accessories and come with...

Brand New Unlocked Apple Iphone 3G 16GB For Sale at just $350USD
We offer 10% discount for any series of Nokia samsung apple iphone you purchase with Free Shipping.and we are in promo now if buy three...

breaking the magic 100MB/s
Hi, Been following your articles on really fast NAS, and sorry, I think I may of just done it :) I have two p5w64's linked via a...

Slideshows

Western Digital ShareSpace QNAP TS-509 Pro D-Link DNS-343 4-Bay Network Storage Enclosure Thecus N3200 RAID 5 NAS D-Link DIR-628 RangeBooster N Dual Band Router Adtran NetVanta 3120 More

Win This!

Enter to Win!

You could win a Promise NetStor NS2300N NAS.

Learn How!

 

Ldr:0.00174021720886, Rct:0.0422110557556, Sky:0.0460691452026, Tlink:0.124269008636, TopPG:0.124353170395, GQV:0.124486207962 seconds to load.