Explain the security risks and protection mechanisms involved in website performance.

Hacking is when somebody gains unauthorised access to data in a system or computer. A hacker will break codes and passwords to get into the computer system which can cause a lot of damage to the system. Unfortunately, even with firewalls preventing hacking it still has occurred to many popular websites including Facebook, Microsoft and Twitter. Twitters systems were hacked early February 2013. The hackers were able to gain access to over 250,000 user accounts including their usernames together with their encrypted and randomised passwords. Phishing is when somebody tries to obtain financial or other confidential information from Internet users, typically by sending an email that looks as if it is from a legitimate organisation but contains a link to a fake website that replicates the real one where information is stolen. Many banks are the target of phishing.


Its purpose is to prevent hacking from occurring. Internet data is transferred between the internet and to the computer through different ports. A firewall manages these ports and controls which programs have access to them. Another way to protect websites is Secure Socket Layers (SSL). Secure Sockets Layer is a computing protocol that ensures the security of data sent via the internet by using encryption. This is done by public key encryption and certificate-based authentication. Key encryption is a random string of numbers created for scrambling and unscrambling data. Encryption keys are designed with algorithms intended to ensure that every key is unpredictable and unique. The longer the key, the harder it is to crack the encryption code. They are used to make sure that hackers cannot understand the data if they are trying to steal personal information. Certificate-based authentication is a digital certificate which is obtained to a system for electronic commerce transactions. ...read more.


1. Personal data shall be adequate, relevant and not excessive. 1. Personal data shall be accurate and where necessary, kept up to date. 1. Personal data processed for any purpose or purposes shall not be kept for longer than is necessary. 1. Personal data shall be processed in accordance with the rights of data subjects under the Act. 1. Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data. 8. Personal data shall not be transferred to a country outside the European Economic Area unless that country ensures an adequate level of protection. Amazon must abide by the Data Protection Act when dealing with their customer?s information. They explain a lot of their policies regarding data protection on their website. They follow the act by allowing information to be updated or removed, allowing customers to provide some but not all information, data will be processed according to different data acts and to not give information to third parties without purpose. ...read more.

