Information Technology · Ch 4 — E-Commerce and E-Governance
Security in E-Commerce
Security in E-Commerce
Keeping online trade safe
Because money and personal data travel over public networks, security is central to e-commerce. If buyers do not trust that their card numbers and personal details are safe, they will not shop online. Security in e-commerce aims to protect transactions and data against theft, alteration and misuse.
The goals of e-commerce security
Good security tries to guarantee four things about every transaction:
- Confidentiality — the information (card number, password, personal details) is seen only by those entitled to see it, not by outsiders.
- Integrity — the data is not changed or tampered with while it travels; the order and amount received are exactly what were sent.
- Authentication — each party is really who they claim to be; the buyer is the genuine account holder and the website is the genuine seller.
- Non-repudiation — a party cannot later deny having made a transaction, because there is reliable proof it took place.
Common threats
- Hacking — unauthorised access to a computer or network to steal or damage data.
- Phishing — fake emails, messages or websites that trick users into revealing passwords, card numbers or OTPs.
- Identity theft — stealing someone's personal or financial details to impersonate them.
- Viruses and malware — harmful programs that damage systems or steal information.
- Credit-card fraud — using stolen card details to make unauthorised purchases.
Security measures and tools
- Encryption — scrambling data into an unreadable form so that even if it is intercepted, an outsider cannot understand it; only the intended recipient can unscramble (decrypt) it. This is the backbone of online security.
- Secure Sockets Layer / Transport Layer Security (SSL/TLS) — the technology behind the padlock symbol and the https in a web address; it encrypts the connection between the buyer's browser and the website so payment details travel safely.
- Digital signatures and digital certificates — used to authenticate parties and confirm that a website or message is genuine and unaltered.
- Firewalls — hardware or software that guards a network, blocking unauthorised access from outside.
- Passwords and two-factor authentication (OTP) — confirm that the genuine user is acting. …
Converting data into a scrambled, unreadable form so that only the intended recipient, who can decrypt it, can understand it — the foundation of s …
Secure Sockets Layer / Transport Layer Security — the technology that encrypts the connection between a browser and a website (shown by 'https' and a padlock), keeping payment an …
A fraud in which fake emails, messages or websites imitate genuine ones to trick users into revealing sensitive information such as passwor …
Hardware or software that monitors and controls traffic into and out of a network, blocking unauthorised access and protecting syst …