Forum Moderators: buckworks

Message Too Old, No Replies

ScanAlert

Hacker Free (so-called testing).

         

babushka99

9:44 am on Sep 27, 2004 (gmt 0)

10+ Year Member



Anyone ever heard or used ScanAlert Service? I think they scan your server everyday for vulnerabilities, etc. and give you a "Site Tested (insert date)" certification that presumably your website has no open vulnerability and your customers will feel secure?

Jambo_ME

4:19 pm on Sep 27, 2004 (gmt 0)

10+ Year Member



Ever walk into a bank and see a sign that says, "Over 30 days robbery free!"?

Anyway, you could just make up your own graphic and save the money.

And what will your service provider think of regular scans?

babushka99

5:32 pm on Sep 27, 2004 (gmt 0)

10+ Year Member



Granted, I agree with you, but I am wondering - you know how gullible (for the lack of any better word) the visitors/buyers to e-commerce websites are. A 3rd party certification saying the site is hack-free or whatever the nomenclature is - might convince them no?

Btw: We have no problems with scans, etc. We are our own service provider. :)

Its like the BBBOnline Icon people see on a website, or SquareTrade Seal, does that make a difference? I am sure it does to many? (I'm just guessing here).

Babs.

ogletree

5:40 pm on Sep 27, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



That bring up a point. Do those certs at the bottom of e-com sites have any real value? I know people that put a lot of effort into getting those. They are all legit ones like BBB and the like. I have even seen the ones like above where they are certified to be hacker free.

Rugles

6:21 pm on Sep 27, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



That company claims that the seal increases sales. Presumable because people feel more comfortable giving up a credit card number.
We don't use them but a sales rep calls me all the time.

SeanW

8:04 pm on Sep 27, 2004 (gmt 0)

10+ Year Member



I wonder how deep they go. If I had to guess, they're just running Nessus (or whatever) against your site. If you have custom code, are they making sure there are no vulnerabilities that way?

Sean

Buddha

9:50 pm on Sep 27, 2004 (gmt 0)

10+ Year Member



We use their service. Although it is not cheap, if you have a big commerce site, it might be worth it to use a service like this and consider it "insurance".

Their daily scans are decent, but if a hacker is really determined, I'm sure they could find a hole which any scanning service would miss. I think the additional value comes when there is a security breach. Their team is very knowledgeable on an individual basis and they can run other server side programs to try to pinpoint the breach.

If you do run into a security breach, the hours of consultation from them on security issues is worth the cost.

As far as conversion, I haven't seen any improvement in conversion. (But we haven't stuck the logo in the best places yet)

Also, if you want CVV response from Amex, you need certification.

nalin

10:14 pm on Sep 27, 2004 (gmt 0)

10+ Year Member



I get sales calls to - its been awhile but I think the rep claimed a 15% conversion increase.

I like nessus better, quite frankly it tests to test - which I can understand and which implies throughness. Testing to get a seal that improves conversion - that doesn't nesecarilly beam confidence to me. If I were to go for commercial testing / certification I would be more inclined to use NetCraft or some other service which I felt was providing value rather then flash.

MrFishGuy

12:23 am on Sep 28, 2004 (gmt 0)

10+ Year Member



Would posting that on your website be an invitation to a hacker to try to crack your site just to prove it wrong?

JenniferL

3:38 am on Sep 28, 2004 (gmt 0)

10+ Year Member



I have gotten sales calls from them before, and my main beef with having that logo on my site is that why on earth should I bring the term "hacker" to the attention of someone who would give us their cc info? Better not to even put the thought in their mind, in my opinion.

Rugles

12:41 pm on Sep 28, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



>>>Better not to even put the thought in their mind, in my opinion.

Good point Jennifer, I never even thought about that.