Skip to content

Information Technology · Ch 4 — E-Commerce and E-Governance

Security in E-Commerce

5

Security in E-Commerce

Keeping online trade safe

Because money and personal data travel over public networks, security is central to e-commerce. If buyers do not trust that their card numbers and personal details are safe, they will not shop online. Security in e-commerce aims to protect transactions and data against theft, alteration and misuse.

The goals of e-commerce security

Good security tries to guarantee four things about every transaction:

  • Confidentiality — the information (card number, password, personal details) is seen only by those entitled to see it, not by outsiders.
  • Integrity — the data is not changed or tampered with while it travels; the order and amount received are exactly what were sent.
  • Authentication — each party is really who they claim to be; the buyer is the genuine account holder and the website is the genuine seller.
  • Non-repudiation — a party cannot later deny having made a transaction, because there is reliable proof it took place.
Common threats
  • Hacking — unauthorised access to a computer or network to steal or damage data.
  • Phishing — fake emails, messages or websites that trick users into revealing passwords, card numbers or OTPs.
  • Identity theft — stealing someone's personal or financial details to impersonate them.
  • Viruses and malware — harmful programs that damage systems or steal information.
  • Credit-card fraud — using stolen card details to make unauthorised purchases.
Security measures and tools
  • Encryption — scrambling data into an unreadable form so that even if it is intercepted, an outsider cannot understand it; only the intended recipient can unscramble (decrypt) it. This is the backbone of online security.
  • Secure Sockets Layer / Transport Layer Security (SSL/TLS) — the technology behind the padlock symbol and the https in a web address; it encrypts the connection between the buyer's browser and the website so payment details travel safely.
  • Digital signatures and digital certificates — used to authenticate parties and confirm that a website or message is genuine and unaltered.
  • Firewalls — hardware or software that guards a network, blocking unauthorised access from outside.
  • Passwords and two-factor authentication (OTP) — confirm that the genuine user is acting. …
Definition 1Encryption

Converting data into a scrambled, unreadable form so that only the intended recipient, who can decrypt it, can understand it — the foundation of s …

Definition 2SSL/TLS

Secure Sockets Layer / Transport Layer Security — the technology that encrypts the connection between a browser and a website (shown by 'https' and a padlock), keeping payment an …

Definition 3Phishing

A fraud in which fake emails, messages or websites imitate genuine ones to trick users into revealing sensitive information such as passwor …

Definition 4Firewall

Hardware or software that monitors and controls traffic into and out of a network, blocking unauthorised access and protecting syst …