The conventional security objectives
Authentication insure the data is come from its origin. Security protocol like HTTPS, SSL can be implemented in connections for Authentication, and we would find them in banks and payment platforms' sites.In the past, most time we saw HTTPS connection on the banks' websites and e-mail websites;however, now, some SNS sites as G+ are also using HTTPS to protect customers' privacy.| G+ with HTTPS |
-
Data confidentiality provide for the protection of data from unauthorized disclosure. This security will use several encryption technology to protect users' privacy, passwords, etc.
- Data integrity is "the representational faithfulness of information to the true state of the object that the information represents, where representational faithfulness is composed of four essential qualities or core attributes: completeness, currency/timeliness, accuracy/correctness and validity/authorization." Data integrity ensure that data is of high quality, correct, consistent and accessible. I think CRC, parity check are used to ensure high quality, correct, consistent; and ECC is used correct wrong part.
Non-repudiation with proof of origin and delivery prevent the purported maker of a statement to successfully challenge the validity of the statement or contract; it is able to check both sender and receiver of the message. This will insures our privacy won't be revealed while transmission.
![]() |
| Foolish Password |
- Even the SN companies & security companies have made great efforts on privacy protection, there won't be any effect if the customers don't care about their security, for example, choosing "111111" or "password" as their passwords. Information security don't care about the most intelligent hackers, but only fear the most foolish users.
social network security objectives
There are three main security objectives: privacy, integrity and availability. Privacy is a protection
of personal information published on their profiles, presumably
accessible by their contacts only. And the messages between certain persons are also been protect. Integrity means the user's identity and related data are protect against unauthorized modification. It could prevent phishing and personating on social websites. Availability means data published by users has to be
continuously available.
I think the difference between them is that conventional security objectives is the fundamental features of a security system, and social networks are also using this features to support security. However, in my opinion, the social network security objectives are not as strict as strict as conventional security objectives as most of the social users don't require the strictest security level. And for economic considerations, to attract more ads, the social network companies more or less have "revealed" users' privacy like Google which I mentioned in my past blog.

Social networking has achieved a level of popularity that requires reasonable access at work, but it is also sufficiently mature to bring value to many businesses. But safe social networking requires an aggressive and layered security strategy at the web gateway, as well as the definition of new usage policies and priorities from management and IT. Better end-user education will also be required to ensure workers use social networking applications safely and appropriately. The combination of layered security and education can help organizations dramatically reduce the risks from malware, phishing, data loss and bandwidth abuse.
回复删除FYI, there is a password generation web site that is easy to use:
回复删除http://www.pctools.com/guides/password/