opinion

Vendor Vigilance — Keeping Eyes on Suppliers

Sometimes the biggest threats to your website’s security may come from those closest to you; such as your employees and the guys writing your code. Beyond the intentionally malicious acts of disgruntled employees or competitive “spies,” simple incompetence and incomplete training regimens can easily lead to disastrous and even unrecoverable results — underscoring the need for proper workplace education and monitoring.

Part of this training (which applies equally well to website owners) involves learning to not just install any “unknown” software application that comes your way — no matter how appealing a particular app may seem.

All the bad guys need to do is put that “free download” app or software online and wait for the fish to bite.

Stick to brand name software whenever possible and you’ll be ahead of the game. While programmers (inhouse or otherwise) have long installed “backdoors” in their code that allows them to gain entrance to a particular system, the scope of these security vulnerabilities was limited, as this access was rarely shared with others. Today, however, the ubiquity of apps and plugins from many different publishers is escalating the issue to problematic proportions.

Open Source software is a culprit in all of this: as userbases swell, the platforms will become prime targets for criminals, who have access to the source code — and a willing audience of free loaders seeking to add the latest geewhiz feature, for free.

All the bad guys need to do is put that “free download” app or software online and wait for the fish to bite. Even if your security system tries to warn you, many folks may still install the program anyway; giving it the permission it needs to carry out its attack.

Android malware attacks initiated by free app installs, for example, were up by nearly 500 percent in 2011, so this isn’t something that just happens to the other guy.

WordPress users are also at risk — due to the enormous range of themes and plugins that are so readily available and tempting to try: one click and your site has a new feature — unfortunately sometimes, those new features are harmful and have access to your FTP information and database.

Sometimes, bad coding is to blame.

For example, a school kid writes a plugin for his computer class and posts it online. Little Billy might have gotten an “F” on that project due to its massive security holes and server resource hogging; but you don’t know that, you just clicked a free download link, thinking, “that’s exactly what I need.”

Other times, professional hackers and identity thieves are at work.

It’s all a matter of being able to trust your vendors; the suppliers that provide your company with its infrastructure — and with its greatest security threat. If you don’t know your vendors, you can’t really trust them; so be careful not to fall into that “free” trap and the bulk of your worries in this regard will be over.

Just remember, when in doubt, leave it out!

Related:  

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More Articles

profile

VerifyMy Seeks to Provide Frictionless Online Safety, Compliance Solutions

Before founding VerifyMy, Ryan Shaw was simply looking for an age verification solution for his previous business. The ones he found, however, were too expensive, too difficult to integrate with, or failed to take into account the needs of either the businesses implementing them or the end users who would be required to interact with them.

Alejandro Freixes ·
opinion

How Adult Website Operators Can Cash in on the 'Interchange' Class Action

The Payment Card Interchange Fee Settlement resulted from a landmark antitrust lawsuit involving Visa, Mastercard and several major banks. The case centered around the interchange fees charged to merchants for processing credit and debit card transactions. These fees are set by card networks and are paid by merchants to the banks that issue the cards.

Jonathan Corona ·
opinion

It's Time to Rock the Vote and Make Your Voice Heard

When I worked to defeat California’s Proposition 60 in 2016, our opposition campaign was outspent nearly 10 to 1. Nevertheless, our community came together and garnered enough support and awareness to defeat that harmful, misguided piece of proposed legislation — by more than a million votes.

Siouxsie Q ·
opinion

Staying Compliant to Avoid the Takedown Shakedown

Dealing with complaints is an everyday part of doing business — and a crucial one, since not dealing with them properly can haunt your business in multiple ways. Card brand regulations require every merchant doing business online to have in place a complaint process for reporting content that may be illegal or that violates the card brand rules.

Cathy Beardsley ·
profile

WIA Profile: Patricia Ucros

Born in Bogota, Colombia, Ucros graduated from college with a degree in education. She spent three years teaching third grade, which she enjoyed a lot, before heeding her father’s advice and moving to South Florida.

Women In Adult ·
opinion

Creating Payment Redundancies to Maximize Payout Uptime

During the global CrowdStrike outage that took place toward the end of July, a flawed software update brought air travel and electronic commerce to a grinding halt worldwide. This dramatically underscores the importance of having a backup plan in place for critical infrastructure.

Jonathan Corona ·
opinion

The Need for Minimal Friction in Age Verification Technology

In the adult sector, robust age assurance, comprised of age verification and age estimation methods, is critical to ensuring legal compliance with ever-evolving regulations, safeguarding minors from inappropriate content and protecting the privacy of adults wishing to view adult content.

Gavin Worrall ·
opinion

Account-to-Account Payments: The New Banking Disruptor?

So much of our industry relies upon Visa and Mastercard to support consumer payments — and with that reliance comes increased scrutiny by both brands. From a compliance perspective, the bar keeps getting raised until it feels like we end up spending half our time making sure we are compliant rather than growing our business.

Cathy Beardsley ·
profile

WIA Profile: Samantha Beatrice

Beatrice credits the sex positivity of Montreal for ultimately inspiring her to pursue work in adult entertainment. She had many friends working in the industry, from sex workers to production teams, so it felt like a natural fit and offered an opportunity to apply her marketing and social media savvy to support people she truly believes in and wants to see succeed.

Women In Adult ·
opinion

Understanding the Latest Server Processors

Over the last decade, we mostly stopped talking about CPU performance. Recently, however, there has been a seismic and exciting change in the CPU landscape, due to innovation by a chip company called Advanced Micro Devices (AMD).

Brad Mitchell ·
Show More