Don’t Use Off The Shelf Ecommerce Shopping Carts
Making money online is pretty simple. Pick a good niche, grab some shopping cart software, chuck it on a web server, get a merchant account, and start advertising.
Really - it's not that hard. But here's a compelling reason NOT TO USE off the shelf ecommerce shopping carts.
Hackers. Hackers buy the same software you do, and then push it through it's paces until they find security holes they can exploit. Because the software is used by 100's if not 1000's of people, they know that once they crack it, they've got a good number of targets.
And because they know the shopping cart software, they know what they have to do to get the information they want.
By investing in a custom made, purpose built shopping cart that doesn't rely on existing libraries - you are adding some mystery into the way your shopping cart works. The hacker doesn't have the benefit of knowing how your site works on the inside, so they have to do ALOT more work and guessing. It's a waste of time to work out how to crack one site if the reward isn't big enough - they aren't going to be able to duplicate their work again and again, so a hacker will move on to bigger fish.
And just because a shopping cart is used by thousands of people doesn't mean it is actually that secure. For example - I was using litecommerce, and discovered that credit card details are stored in a database in plain text. There are exploits available online right now that will give you access to shopping carts running litecommerce, and all the customer details they hold such as... credit card details. Yeah.
Anyway - off the shelf software is good to kick start you in half a minute, but I really recommend asking someone to develop a custom solution for you from scratch.
Recent blog posts
- Too much to fit into a twitter update!
- Function Before Form
- Feedburner - The Newsletter Alternative?
- Paused Adsense, but the traffic keeps coming.
- Amazon S3 Is Nice
- listen to RSS feeds with Odiogo.com
- US Army warns of Twitter Terrorist Threat
- $350 generates $12,000+
- MYSQL Versus File System For Storage
- I'm a Drupal Contributor!


LC doesn't have to store CC information. I run it and use eway as the payment provider- it hooks straight into eway and I never see the credit card information. It's not stored in my database at all
- reply
Submitted by Anonymous on 2 September 2008 - 2:46pm.Using eway as the payment provider you won't see any CC information because it is never stored - it is passed on to the processor - ie eway.
If you process credit cards manually, the cc information has to be stored - and when it is stored, it is done in plain text.
- reply
Submitted by Michael Phipps on 3 September 2008 - 9:26am.Post new comment