Claim Missing Document
Check
Articles

Found 2 Documents
Search
Journal : Journal of Computer Science and Informatics Engineering (J-Cosine)

Implementasi GNU Privacy Guard (GPG) Hybrid Encryption untuk Meningkatkan Keamanan Informasi pada Layanan Electronic Signature (E-Sign) Universitas Mataram Mardiansyah, Ahmad Zafrullah; Zubaidi, Ariyan; Jatmika, Andy Hidayat; Huwae, Raphael Bianco
Journal of Computer Science and Informatics Engineering (J-Cosine) Vol 8 No 1 (2024): Juni 2024
Publisher : Informatics Engineering Dept., Faculty of Engineering, University of Mataram

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.29303/jcosine.v8i1.593

Abstract

Electronic signatures have been widely used for administrative purposes since 2020, especially when activities from home are a priority. University of Mataram is one of the state universities that provides electronic signature facilities (E-Sign) for its academic community. The ease of using E-Sign has its own obstacles, one of which is in terms of security protection. Protection in the information security system has a role to take preventive action if the worst scenario occurs to the information system, such as unauthorized access by hackers. Naturally, each signature has been given information related to several things, namely who signed, when it was signed, information for signature purposes, and hash values that can be used to ensure the integrity of the data from the signature. When unauthorized access occurs, hackers can create an identity using the identity of a particular person. This makes E-Sign validation difficult and potentially misused. In this study, a scheme for securing user identity is proposed using GNU Privacy Guard (GPG) to encrypt E-Sign data. The encryption process is carried out with two layers of public-private key cryptography combined with the PGP Key Server.
Security Analysis of the Lombok Tourism Android Application Using Penetration Testing (Pentesting) Methods Based on the OWASP Mobile Top 10-2024 Framework Ida Bagus Adi Surya Kemenuh; Huwae, Raphael Bianco; Jatmika, Andy Hidayat
Journal of Computer Science and Informatics Engineering (J-Cosine) Vol 9 No 1 (2025): Juni 2025
Publisher : Informatics Engineering Dept., Faculty of Engineering, University of Mataram

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.29303/jcosine.v9i1.624

Abstract

Android has become the most widely used operating system for mobile devices, playing a crucial role in supporting the tourism sector. As tourism in Indonesia grows, the demand for quick and easy access to information for travel planning has increased. However, concerns about the security of user data in Android applications have emerged. This study focuses on penetration testing of tourism-related Android applications in Lombok to identify vulnerabilities, particularly based on the OWASP Top 10 Mobile Risks. Using static analysis with the Mobile Security Framework (MobFS), two critical vulnerabilities were identified: Insecure Data Storage and Insufficient Cryptography. Penetration testing revealed that although there was a risk related to insecure data storage, no sensitive user data was found in the application's database. The application was also found to use outdated encryption (CBC with PKCS7 padding), which could expose it to padding oracle attacks. This research emphasizes the need for robust security measures in mobile applications within the tourism sector.