opinion

Vendor Vigilance — Keeping Eyes on Suppliers

Sometimes the biggest threats to your website’s security may come from those closest to you; such as your employees and the guys writing your code. Beyond the intentionally malicious acts of disgruntled employees or competitive “spies,” simple incompetence and incomplete training regimens can easily lead to disastrous and even unrecoverable results — underscoring the need for proper workplace education and monitoring.

Part of this training (which applies equally well to website owners) involves learning to not just install any “unknown” software application that comes your way — no matter how appealing a particular app may seem.

All the bad guys need to do is put that “free download” app or software online and wait for the fish to bite.

Stick to brand name software whenever possible and you’ll be ahead of the game. While programmers (inhouse or otherwise) have long installed “backdoors” in their code that allows them to gain entrance to a particular system, the scope of these security vulnerabilities was limited, as this access was rarely shared with others. Today, however, the ubiquity of apps and plugins from many different publishers is escalating the issue to problematic proportions.

Open Source software is a culprit in all of this: as userbases swell, the platforms will become prime targets for criminals, who have access to the source code — and a willing audience of free loaders seeking to add the latest geewhiz feature, for free.

All the bad guys need to do is put that “free download” app or software online and wait for the fish to bite. Even if your security system tries to warn you, many folks may still install the program anyway; giving it the permission it needs to carry out its attack.

Android malware attacks initiated by free app installs, for example, were up by nearly 500 percent in 2011, so this isn’t something that just happens to the other guy.

WordPress users are also at risk — due to the enormous range of themes and plugins that are so readily available and tempting to try: one click and your site has a new feature — unfortunately sometimes, those new features are harmful and have access to your FTP information and database.

Sometimes, bad coding is to blame.

For example, a school kid writes a plugin for his computer class and posts it online. Little Billy might have gotten an “F” on that project due to its massive security holes and server resource hogging; but you don’t know that, you just clicked a free download link, thinking, “that’s exactly what I need.”

Other times, professional hackers and identity thieves are at work.

It’s all a matter of being able to trust your vendors; the suppliers that provide your company with its infrastructure — and with its greatest security threat. If you don’t know your vendors, you can’t really trust them; so be careful not to fall into that “free” trap and the bulk of your worries in this regard will be over.

Just remember, when in doubt, leave it out!

Related:  

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More Articles

opinion

Why Retail Expertise Is Essential When AI Tools Analyze Store Data

Somewhere in one of our stores, someone scanned a barcode into a quantity field. The number entered was 8,388,607. At $19.99 per unit, that made a single line item worth roughly $167 million. The number was so large that the import failed immediately.

Zondre Watson ·
profile

Vendo CEO Mitch Platt Reflects on 20 Years of Lessons and Evolution

More than 20 years ago, three entrepreneurs in Barcelona began gathering over beers to pitch, dissect and routinely destroy one another's business ideas. The ritual was simple: One person arrived with a concept, while the other two tried to expose every weakness. Any proposal that survived earned another look. Most did not.

Jackie Backman ·
opinion

How to Avoid the Hidden Risks of AI-Generated Legal Documents

Artificial intelligence can write a contract in seconds, but that does not mean it can write the contract your business actually needs. Across the adult industry, operators, creators and producers are increasingly using generative AI to prepare model releases, performer agreements, privacy policies, takedown notices, employment documents and responses to regulators. The appeal is obvious: Legal work is expensive, AI is fast and the resulting document often looks impressively professional. That polished appearance is exactly what makes the practice dangerous.

Corey Silverstein ·
opinion

How Rolling Reserves Affect Cash Flow and Merchant Stability

You log in to your payment processor’s dashboard, discover they are withholding 10% of your sales, and immediately assume something has gone wrong. In reality, everything is working exactly as intended.

Jonathan Corona ·
opinion

What Federal Age Verification Could Mean for Adult Websites

Our industry has grappled with a patchwork of confusing and burdensome state age verification laws for the past couple of years. But that landscape could change quickly after the House passed the Kids Internet and Digital Safety (KIDS) Act (H.R. 7757) by a vote of 267-117, marking a significant federal step into this space.

Lawrence G. Walters ·
opinion

The Website Footer Requirements Every Adult Merchant Should Know

Since I started in this business 25 years ago, I've watched website footers evolve from a simple collection of links designed to help with SEO into important tools for meeting compliance and regulatory requirements, improving the customer experience and reducing chargebacks.

Cathy Beardsley ·
opinion

Why E-Payment Diversification Matters for Merchant Stability

Match payment methods to your customers. Look at where your customers are located, how they prefer to pay and which products they purchase. A business with significant European traffic may benefit from SEPA or Pay by Bank, while a subscription-based business may prioritize ACH or cryptocurrency. Add the payment methods your customers are most likely to use, as not every option is available.

Jonathan Corona ·
trends

AI at Work: The Tools and Practices Powering Creativity, Commerce and Compliance

For years, artificial intelligence felt like the plot of a science-fiction movie. Pop culture gave us Skynet from “The Terminator,” the replicants of “Blade Runner” and countless visions of machines replacing human creativity altogether. AI was cast as either humanity's next great breakthrough or the beginning of a dystopian future.

Jackie Backman ·
opinion

Key Questions Online Merchants Should Know About PCI Compliance

Choosing a payment provider involves more than comparing features and pricing. It's also about trusting that your customers' payment information is being handled securely. Every August, Segpay is recertified as a Level 1 PCI-compliant service provider, a milestone the company has achieved for the past 20 years. Having helped write Segpay's original PCI policy documents more than two decades ago, I've seen firsthand how PCI compliance has evolved.

Cathy Beardsley ·
profile

New Moon Network's Savannah Sly on Turning Lived Experience Into Advocacy

Savannah Sly is the first to admit she didn't always understand sex work. At 18, she was an art student in Boston, working part-time at a box office and, as she puts it, "broke as a joke." While looking for ways to make ends meet, she often found herself browsing Craigslist's adult ads, intrigued by the women advertising their services.

Jackie Backman ·
Show More