Web site security vulnerabilities are a common problem but few web site owners, business operators or even web designers truly understand the nature of the problem.
I wrote some time ago about why web site security is important for everyone but it is a hard concept to communicate to people who have little or no understanding of the technology involved in hosting a web site, Internet service or e-commerce business.
So this article is an attempt to make a non-technical comparison which can be understood by anyone.
Imagine you own a Conference Centre (your website). This facility has lots of rooms (pages) and attracts hundreds of attendees (visitors or customers computers) every day. Some attendees will come regularly for different courses or will cover the same course over and over again.
Other attendees may have a quick look around and decide they aren't ready to do a course just yet. But may come back later.
Unbeknown to you, one of the training rooms has a broken lock on the fire exit (vulnerability) through which every day a hypnotist enters.
This hypnotist is a nasty person (malware) and he quickly hypnotises (infects) everyone in the room. He tells them to gather as much information on the financial transactions of those around them as they can. Then, when they hear the keyword "download", they will divulge all the information they have gathered and forget what they have done.
So the attendees go off about their day-to-day activities and, without realising what they're doing, quietly gather the information.
They collect the bank statements and account details of their family and loved ones, they watch as people enter PIN numbers at the checkout and they copy down and skim credit card details.
They also collect security codes, PIN numbers and password used for non-financial purposes because they know people reuse them frequently and they may be useful.
Then, a few days later a phone call arrives and the keyword is mentioned. The attendee passes everything they have gathered to the hypnotist.
Days, weeks or months pass before anyone starts noticing. First it's a card transaction declined. Then it's bailiffs calling round and before long the reason is understood - the family and friends of the attendee have been the victims of identity theft and fraud, and have lost thousands.
Tens, hundreds or even thousands of people have been robbed of thousands or even millions of pounds.
Eventually, the auhorities trace the cause of the problem back to the Conference Centre but there's no sign of the hypnotist.
All that happens now is the attendees lose confidence in the Conference Centre and stop coming. Very quickly the centre goes out of business.
And all because the owner of the conference centre didn't make sure the facility was secure.
I wrote some time ago about why web site security is important for everyone but it is a hard concept to communicate to people who have little or no understanding of the technology involved in hosting a web site, Internet service or e-commerce business.
So this article is an attempt to make a non-technical comparison which can be understood by anyone.
Imagine you own a Conference Centre (your website). This facility has lots of rooms (pages) and attracts hundreds of attendees (visitors or customers computers) every day. Some attendees will come regularly for different courses or will cover the same course over and over again.
Other attendees may have a quick look around and decide they aren't ready to do a course just yet. But may come back later.
Unbeknown to you, one of the training rooms has a broken lock on the fire exit (vulnerability) through which every day a hypnotist enters.
This hypnotist is a nasty person (malware) and he quickly hypnotises (infects) everyone in the room. He tells them to gather as much information on the financial transactions of those around them as they can. Then, when they hear the keyword "download", they will divulge all the information they have gathered and forget what they have done.
So the attendees go off about their day-to-day activities and, without realising what they're doing, quietly gather the information.
They collect the bank statements and account details of their family and loved ones, they watch as people enter PIN numbers at the checkout and they copy down and skim credit card details.
They also collect security codes, PIN numbers and password used for non-financial purposes because they know people reuse them frequently and they may be useful.
Then, a few days later a phone call arrives and the keyword is mentioned. The attendee passes everything they have gathered to the hypnotist.
Days, weeks or months pass before anyone starts noticing. First it's a card transaction declined. Then it's bailiffs calling round and before long the reason is understood - the family and friends of the attendee have been the victims of identity theft and fraud, and have lost thousands.
Tens, hundreds or even thousands of people have been robbed of thousands or even millions of pounds.
Eventually, the auhorities trace the cause of the problem back to the Conference Centre but there's no sign of the hypnotist.
All that happens now is the attendees lose confidence in the Conference Centre and stop coming. Very quickly the centre goes out of business.
And all because the owner of the conference centre didn't make sure the facility was secure.