SOFTWARE DEVELOPMENT ENGINEER |
| SOFTWARE DEVELOPMENT ENGINEER Imagine the chance to work for the global leader in e-commerce ... |
|
Web Developer |
| "WE NEED A WEB DEVELOPER." Expanding business in motorsports is seeking an internet ... |
|
Lead Graphic Web Designer |
| TriVita, Inc. ( ) is an Integrated Health Company located in the Scottsdale Airpark is ... |
|
.net developers |
| We have several Permanent and contracting positions for the following skills: One have 3+ years of ... |
|
Performance Analyst |
| RESPONSIBILITIES: The Performance Analyst is accountable for assisting in the communication and ... |
|
.NET Developer |
| Web Application Developer - Full-Time, Permanent position Position responsibilities include ... |
|
Communications Specialist |
| Communications Specialist Job Description: Candidate should be experienced Communications and or PR ... |
|
Integration Engineer |
| PetSmart, Inc. (NASDAQ: PETM) is the largest specialty retailer of services and solutions ... |
|
Java Engineer |
| Java Engineer Job Description: Actively participate in design and development of new and existing ... |
|
Web Developer/Web Master |
| The Rich Dad Company in Scottsdale is looking for a dynamic, self-motivated, front-end web ... |
|
|
Ecommerce sites panned for lack of security testing
|
Despite a series of high-profile online security blunders at leading retailers such as Argos and B&Q in recent years, companies selling online are still failing to train staff to look for bugs and glitches which could betray customer details or give rise to fraud.
While sophisticated hackers might always find a way into a system, many companies, such as the two mentioned above, are guilty of some basic failings which would have been discovered within minutes of penetration testing, according to a leading expert.
Dan Newman has been running one of the most popular certified ethical hacking courses for three years at the UK-based Training Camp and says he's not seen a single student from an ecommerce company put forward to attend, while financial institutions, government departments and the military are well up on the need for penetration testing.
"We had one guy who worked for a retailer but he funded it himself because he was actually looking to move into a new job in a different sector," said Newman.
While this doesn't mean ecommerce sites have never honed their penetration-testing skills, Newman is confident he'd have seen some of them through his classroom at least, or heard of their efforts if such skills were commonly used in the online retail sector.
Newman walkedthrough a very basic 'hack' which simply involves changing cookies to access any number of customers' details on one ecommerce website. By doing so a hacker would be able to download paid-for documents from other users' accounts with one keystroke.
Newman blames a lot of the failings on the pressures of the retail environment and on developers charged with getting functionality online in time to meet demand, rather than when it is ready.
"I used to be a developer and I used to make the same mistakes they do," said Newman.
Newman said a lot of the time "they're getting things out there as quickly as they can" without regard for security.
"Some websites are just bulging at the seams," said Newman, referring to the multitude of security weaknesses just waiting to be exploited in the ecommerce sector.
Firebox.com is one online retailer happy to talk about its penetration testing. A spokeswoman for the firm confirmed it continually tests its perimeters and is pleased with the results of such vigilance.
"Our IT team regularly check all of our security and always start with anywhere there could be a potential problem and thankfully they have always been pleasantly surprised but you still have to test," said the spokeswoman. "This is our business and if shoppers are going to feel confident shopping online then security is our bread and butter."
But others aren't so responsible and put too much faith in partners and third parties, said Newman.
"I feel bad for a lot of companies who buy products from vendors who know nothing of security," added Newman. But just because e-tailers deal with a third party vendor doesn't abdicate responsibility for carrying out their own thorough penetration testing.
Ecommerce sites are facing stricter regulation in the wake of serious security failings.
|
| Related jobs |
|
|
Process Engineer Willows - (JC11152)
If you want a career that offers growth, opportunity and inspiration, consider what is waiting for you at Johns Manville. We've been developing leading edge commercial, ...
|
|
|
Process Engineer Willows - (JC11099)
If you want a career that offers growth, opportunity and inspiration, consider what is waiting for you at Johns Manville. We've been developing leading edge commercial, ...
|
|
|
Geotechnical Engineer - CFE
Description: Exciting Geotechnical Engineer career opportunity in sunny Northern California with employee owned firm. CH2M HILL is a full-service, global engineering and ...
|
|
|
Senior Transportation Planner/Engineer
Transportation Project Manager Currently we have immediate openings in our four California offices for an experienced Transportation Project Manager/Planner. ...
|
|
|
Quality Assurance Team Leader
Job ID: Title: Quality Assurance Team Leader Company: The Coca-Cola Company Location: CA - Mt. Shasta Specific Location: CCDA Waters LLC Job Type: Full Time Relocation P...
|
|
|
Civi Engineer with PG&E
Our energy flows through you! At Pacific Gas and Electric Company, we recognize that our employees are the backbone of our success. It's the mix of talent, ...
|
|
|
Structural Engineer-EDG
Description: We are looking for a talented, journeyman level Structural Engineer to support public works projects and water/wastewater infrastructure projects throughout ...
|
|
|
Construction Project Engineer
Construction Project Engineer for Heavy Civil Construction Company. Provide job site technical support in negotiations, plan reading, layout and quality control.&...
|
|
|
Sr Tech Support Engineer II
Raytheon Technical Services Company LLC (RTSC) provides technical, scientific, and professional services for defense, federal, and commercial customers worldwide. RTSC ...
|
|
|
Geotechnical Engineer
Project Geotechnical Engineer Duties: Studies and analyzes surface and subsurface soils to determine characteristics for construction, development or land ...
|
|
| Related press releases |
|
|
UK emailers backstabbing and immoral
UK workers are using email to run-down their colleagues and improve their own chances of securing important promotions.
More than half the white-collar workers in Lond...
|
|
Two weeks to outlaw porn" - Ford tells staff
US car giant Ford has warned its 20,000 UK workers to get rid of offensive material from their computers or face the sack.
Workers have until Friday 15 March to remove...
|
|
IBM and EMC: it's handbags at dawn
Big Blue claims EMC's latest Network Attached Storage (NAS) offering, titled Celerra, is "unworkable".
IBM claims EMC's NAS software, which was unveiled last week, wil...
|
|
Cyber-criminals face high-tech 'home guard
A new initiative has been launched to put the high-tech expertise of the UK IT industry at the disposal of the police investigating cyber-crime.
At an industry meeting...
|
|
Top 10 tips for surviving the euro
A survey released yesterday showed that around 60 per cent of the UK's technology suppliers have yet to prepare for the introduction of the euro.
Even though the UK is...
|
|
That'll do nicely: IBM seals $4bn Amex deal
American Express is hoping to slash its IT budget, which runs to hundreds of millions of dollars, by outsourcing a significant slice of its infrastructure to IBM.
Big ...
|
|
No' vote gathering support in HP merger row
Black clouds are gathering over Hewlett Packard's Palo Alto headquarters today as it emerges that the majority of employees and one of the company's larger investors are ...
|
|
PCs: the environmental cost
Obsolete computers from the west are causing an ecological disaster in developing countries, despite schemes encouraging consumers to recycle them.
A report by a coali...
|
|
HP-Compaq opposition gathers strength
Opposition to the HP-Compaq merger is growing stronger following analyst support for Walter Hewlett's alternative to the deal.
A Wall Street analyst said she agreed wi...
|
|
|
|