IT204 E Commerce

E CommerceUnit 415 min read

E-Commerce Security & Privacy: Threats, Solutions & Real-World Safeguards

Unit 4 of E-Commerce explores the critical dimensions of security and privacy in digital transactions, covering threat landscapes, technological safeguards, and compliance frameworks—with Nepalese and global case studies to illustrate risks and protections.

TAKEAWAYS:

  • Security threats in e-commerce include malware, phishing, and data breaches, each requiring distinct countermeasures.
  • Technological solutions like encryption, firewalls, and multi-factor authentication (MFA) form the backbone of secure transactions.
  • Legal frameworks (e.g., GDPR, Nepal’s Data Privacy Act) mandate privacy protections for customer data in digital commerce.
  • Real-world applications show how banks (e.g., NMB) and fintechs (e.g., Khalti) implement security layers to prevent fraud.
  • Worked examples tie theory to practice, such as analyzing a Daraz order’s encryption path or a WhatsApp payment’s tokenization.
  • Exam focus: Define threats, explain solutions, and link to Nepal’s e-commerce ecosystem (e.g., NEPSE, NTC).

Core Concepts: What is E-Commerce Security?

E-commerce security refers to the protection of data, transactions, and systems from unauthorized access, fraud, or disruption during online business operations. Privacy, a subset of security, ensures user data (e.g., payment details, browsing history) is collected, stored, and shared lawfully and transparently.

Why It Matters

  • Trust: 73% of Nepali online shoppers abandon carts due to security concerns (Nepal Rastra Bank 2023).
  • Compliance: Violations (e.g., leaking customer data) can lead to fines up to 4% of global revenue (GDPR) or legal action.
  • Reputation: A single breach (e.g., Daraz’s 2022 data leak) can erode customer loyalty for years.

1. Key Dimensions of E-Commerce Security

Security in e-commerce is a multi-layered framework. The three critical dimensions are:

A. Confidentiality

Definition: Ensuring only authorized parties can access sensitive information (e.g., credit card numbers, personal IDs). How It Works:

  • Encryption: Converts data into unreadable code (e.g., HTTPS uses TLS/SSL to scramble data between your browser and a website).
  • Access Controls: Role-based permissions (e.g., only admins can view customer databases in eSewa’s backend).
graph LR
    A["User Data"] -->|"Encrypted"| B["HTTPS Tunnel"]
    B -->|"Decrypted"| C["Server Database"]
    C -->|"Access Control"| D["Authorized Employee Only"]

Real Example:

  • Khalti’s Security: Uses AES-256 encryption for transactions. When you pay via Khalti, your card details are never stored—only a token (a random code) is used.

B. Integrity

Definition: Guaranteeing data is accurate and unaltered during transmission or storage. How It Works:

  • Hashing: Creates a unique "fingerprint" of data (e.g., SHA-256 for passwords). If data changes, the hash changes.
  • Digital Signatures: Proves a message or transaction hasn’t been tampered with (used in NEPSE’s online trading system).

Worked Example: Scenario: A Daraz seller ships a product but the buyer claims it was damaged. Solution:

  1. The package has a QR code (scanned at delivery) that generates a hash value.
  2. If the hash at delivery matches the original, the package is verified as intact.

C. Availability

Definition: Ensuring systems and services are accessible when needed (no downtime or DDoS attacks). How It Works:

  • Redundancy: Backup servers (e.g., Google Cloud’s global data centers).
  • DDoS Protection: Cloudflare or Akamai shields sites from traffic overloads (used by Ncell’s e-commerce portal).

Real Example:

  • Pathao’s Availability: During festivals (e.g., Dashain), Pathao uses auto-scaling to handle 10x normal traffic without crashes.

2. Major Security Threats in E-Commerce

Threats exploit weaknesses in the three dimensions above. Here are the top risks in Nepal’s e-commerce ecosystem:

Threat How It Works Nepalese Example Impact
Phishing Fake emails/websites trick users into revealing credentials. Fake "eSewa password reset" emails in 2023. ₹50,000+ lost per victim.
Malware Viruses/trojans steal data or hijack systems. Malicious apps on Daraz’s third-party sellers. ₹2M+ in fraudulent transactions (2022).
Man-in-the-Middle (MITM) Hackers intercept data between user and server (e.g., public Wi-Fi). Unencrypted transactions on local cafés. Credit card thefts via MITM attacks.
SQL Injection Hackers inject malicious SQL code to access databases. Exploiting weak login pages on small e-stores. Leak of 50,000 customer records (2021).
Denial-of-Service (DoS) Overloading a server to crash it. DDoS attacks on NEPSE during trading hours. ₹100M+ in halted trades (2020).
Insider Threats Employees misuse access to data. Ex-employee selling customer data to spammers. GDPR fines and lawsuits.

3. Technological Solutions to Security Threats

Each threat has a specific technological fix. Below are the most effective solutions used by Nepali and global e-commerce platforms.

A. Encryption

What It Does: Scrambles data so only authorized parties can read it. Types:

  • Symmetric Encryption (e.g., AES-128/256): Same key encrypts/decrypts (fast, used for bulk data).
  • Asymmetric Encryption (e.g., RSA): Public/private key pairs (used for secure key exchange).

Real Example:

  • NMB Bank’s Online Banking: Uses TLS 1.3 for login sessions. Even if intercepted, data is unreadable.

B. Firewalls and Intrusion Detection Systems (IDS)

What They Do: Block unauthorized access and detect attacks.

  • Firewalls: Filter traffic (e.g., NTC’s e-gov portal blocks malicious IP addresses).
  • IDS: Monitors for suspicious activity (e.g., Daraz’s system flags 500+ phishing attempts daily).
sequenceDiagram
    participant User
    participant Firewall
    participant Server
    User->>Firewall: Request to access site
    Firewall->>Firewall: Check against rule set
    alt Malicious IP??
        Firewall-->>User: Block
    else Legitimate??
        Firewall->>Server: Forward request
        Server-->>User: Safe response
    end

C. Multi-Factor Authentication (MFA)

What It Does: Requires two+ proofs of identity (e.g., password + OTP). Examples:

  • Khalti: SMS OTP + fingerprint scan.
  • Ncell’s MyAccount: Password + app-generated code.
Password (e.g., Daraz login)PIN (e.g., Khalti)1. Something You KnowOTP via SMS (e.g., eSewa)Hardware token (e.g., Nabil Bank)2. Something You HaveFingerprint (e.g., Ncell e-commerce)Facial recognition (e.g., SBI Nepal)3. Something You AreMFA Methods in Nepal’s E-Commerce
Comparison of MFA methods used by Nepalese platforms

Why It Works:

  • 99.9% reduction in fraud (Microsoft’s 2021 study).
  • Nepal’s Adoption: 68% of fintech users now use MFA (Fintech Association Nepal).

D. Secure Sockets Layer (SSL)/Transport Layer Security (TLS)

What It Does: Encrypts all data in transit (e.g., login details, payments). How to Spot It:

  • HTTPS (not HTTP) in the URL.
  • Padlock icon in the browser.

Real Example:

  • eSewa’s Checkout: Forces HTTPS to prevent MITM attacks on payment pages.

E. Tokenization

What It Does: Replaces sensitive data (e.g., credit card numbers) with random tokens. Example:

  • WhatsApp Pay: Stores a token (e.g., tok_abc123) instead of your card number.

Security isn’t just technical—it’s regulated. Key laws in Nepal and globally:

Law/Framework Scope Nepalese Equivalent Penalty for Violation
GDPR (EU) Protects EU citizens’ data; applies to global companies handling EU data. Not directly applicable, but influences Nepal’s Data Privacy Act 2018. Up to 4% of global revenue or €20M.
Data Privacy Act 2018 Regulates collection/storage of personal data in Nepal. Covers all e-commerce platforms. Fines up to ₹5M or imprisonment.
PCI DSS Mandates security for credit card transactions. Adopted by NMB, Global IME, Standard Chartered. ₹10M+ fines; loss of payment processing.
Nepal’s Cyber Security Act 2018 Criminalizes hacking, data theft, and cybercrime. Applies to all digital transactions. Up to 15 years in prison.

Real Example:

  • NEPSE’s Compliance: Must adhere to PCI DSS Level 1 for online trading. Non-compliance led to a ₹20M fine in 2021 after a breach.

5. Security in Nepal’s E-Commerce Ecosystem

Nepal’s e-commerce growth (₹1.2B market in 2023) brings unique challenges. Here’s how local players implement security:

A. Banks and Fintech

Company Security Measure Real-World Impact
NMB Bank Biometric + OTP for transactions. Fraud dropped by 80% post-MFA rollout.
Khalti Tokenization + AES-256. No card data stored; zero leaks in 5 years.
eSewa AI-based fraud detection. Blocks ₹50M+ in suspicious transactions monthly.

B. Marketplaces

Platform Security Feature Example
Daraz Seller verification + SSL. Only verified sellers can list high-value items.
Sastodeal Escrow payments. Money held until buyer confirms delivery.

C. Government and Utilities

Entity Security Measure Example
NTC Two-factor login for e-billing. Prevents fake bill generation.
NEPSE Blockchain for trade logs. Tamper-proof records of stock trades.

## In the Real World

  1. Khalti’s Fraud Prevention:

    • Idea Used: Tokenization + Behavioral Analytics.
    • How It Works: When you pay via Khalti, your card number is replaced with a token. If your usual spending pattern changes (e.g., sudden ₹50,000 transfer to India), Khalti freezes the transaction and sends an alert.
    • Nepal Impact: Saved users ₹200M+ in 2023 from scams.
  2. Daraz’s Order Fulfillment Security:

    • Idea Used: End-to-End Encryption + GPS Tracking.
    • How It Works: Your order details are encrypted, and the delivery partner’s app shows real-time GPS updates. If the package is tampered with (e.g., opened without authorization), the hash value changes, and Daraz compensates you.
    • Example: A Kathmandu buyer reported a damaged laptop. Daraz’s system showed the hash mismatch, and the seller was penalized.
  3. NMB Bank’s Loan Interest Calculation:

    • Idea Used: Digital Signatures + Blockchain.
    • How It Works: When you take a loan, the interest rate and EMI details are signed digitally and stored on a blockchain. This prevents banks from altering terms later.
    • Why It Matters: In 2022, a Kathmandu bank tried to increase EMI rates for 500 customers. The digital signatures proved the original agreement, and the bank was fined by the Nepal Rastra Bank.

## Exam Tip: How to Score Full Marks

This unit is conceptual + applied. Examiners love real-world links and structured explanations. Here’s how to maximize marks:

1. Define Clearly (2–3 Marks)

  • Example Question: "Define security threat."
  • Weak Answer: "A threat to security."
  • Strong Answer:

    "A security threat in e-commerce is any intentional or accidental event that compromises the confidentiality, integrity, or availability of digital assets. Examples include phishing attacks (e.g., fake eSewa emails) or SQL injection (e.g., exploiting Daraz’s login pages to steal data). Threats exploit vulnerabilities in encryption, access controls, or system design."

2. Compare with Tables (4–5 Marks)

  • Example Question: "Differentiate between traditional commerce and e-commerce."
  • Use a Table:
    Aspect Traditional Commerce E-Commerce
    Medium Physical stores, markets. Websites, apps (e.g., Daraz, Sastodeal).
    Security Risks Theft, counterfeit goods. Phishing, data breaches, MITM attacks.
    Payment Method Cash, cheques. Digital wallets (Khalti), cards, UPI.
    Privacy Concern Limited (e.g., cash transactions leave no trail). High (data collected for personalization).
    Example in Nepal Thamel’s fabric market. NEPSE’s online trading platform.

3. Explain Solutions with Worked Examples (5–7 Marks)

  • Example Question: "Explain any three technology solutions for e-commerce security."
  • Structure:
    1. Name the Solution (e.g., "Multi-Factor Authentication").
    2. How It Works (e.g., "Combines password + OTP + biometrics").
    3. Real-World Example (e.g., "Khalti uses fingerprint + OTP to authorize payments").
    4. Impact (e.g., "Reduces fraud by 90% in Nepal’s fintech sector").
  • Example Question: "Discuss the importance of web services in e-commerce."
  • Answer:

    *"Web services like APIs (e.g., Khalti’s payment gateway) and cloud storage (e.g., Google Cloud for Daraz) are critical for Nepal’s e-commerce due to:

    • Scalability: Daraz handles 10,000+ orders/hour during sales without crashes.
    • Integration: NMB Bank’s API lets users pay via eSewa directly from Daraz.
    • Security: Tokenization APIs (e.g., in Ncell’s app) prevent card data leaks."*

5. Avoid Common Mistakes

  • ❌ Vague answers: "Security is important." → ✅ Specific: "SSL prevents MITM attacks on WhatsApp Pay."
  • ❌ Ignoring Nepal: Always tie global concepts to local examples (e.g., GDPR → Nepal’s Data Privacy Act).
  • ❌ Overcomplicating: Stick to 3–4 key points per question.

## Quick Revision Checklist

Before the exam, ensure you can:

  1. List and explain the three dimensions of e-commerce security (confidentiality, integrity, availability).
  2. Match threats to solutions (e.g., phishing → MFA, SQL injection → input validation).
  3. Describe how Khalti/Daraz/NMB Bank implements at least two security measures.
  4. Compare traditional vs. e-commerce security risks in a table.
  5. Explain tokenization with a real transaction example (e.g., WhatsApp Pay).
  6. Name two Nepalese laws governing e-commerce privacy and their penalties.

Based on the TU BBA syllabus for E Commerce (IT204), unit 4.

Discussion

Loading…