Don’t Use Off The Shelf Ecommerce Shopping Carts

Making money online is pretty simple.  Pick a good niche, grab some shopping cart software, chuck it on a web server, get a merchant account, and start advertising.

Really - it's not that  hard.  But here's a compelling reason NOT TO USE off the shelf ecommerce shopping carts.

Hackers.  Hackers buy the same software you do, and then push it through it's paces until they find security holes they can exploit.   Because the software is used by 100's if not 1000's of people, they know that once they crack it, they've got a good number of targets.

And because they know the shopping cart software, they know what they have to do to get the information they want.

By investing in a custom made, purpose built shopping cart that doesn't rely on existing libraries - you are adding some mystery into the way your shopping cart works.  The hacker doesn't have the benefit of knowing how your site works on the inside, so they have to do ALOT more work and guessing.  It's a waste of time to work out how to crack one site if the reward isn't big enough - they aren't going to be able to duplicate their work again and again, so a hacker will move on to bigger fish.

And just because a shopping cart is used by thousands of people doesn't mean it is actually that secure.  For example - I was using litecommerce, and discovered that credit card details are stored in a database in plain text.  There are exploits available online right now that will give you access to shopping carts running litecommerce, and all the customer details they hold such as... credit card details.  Yeah.

Anyway - off the shelf software is good to kick start you in half a minute, but I really recommend asking someone to develop a custom solution for you from scratch.

Litecommerce

LC doesn't have to store CC information. I run it and use eway as the payment provider- it hooks straight into eway and I never see the credit card information. It's not stored in my database at all

Submitted by Anonymous on 2 September 2008 - 2:46pm.
Using eway as the payment

Using eway as the payment provider you won't see any CC information because it is never stored - it is passed on to the processor - ie eway.

If you process credit cards manually, the cc information has to be stored - and when it is stored, it is done in plain text.

Submitted by Michael Phipps on 3 September 2008 - 9:26am.

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.

Post new comment

  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
Image CAPTCHA
Copy the characters (respecting upper/lower case) from the image.