The recently discovered/fixed gap in ecommerce security got me wondering about
an article I just read. Sen. Dianne Feinstein is re-introducing a bill that is
supported by the United States Direct Marketing Association that would require
businesses to notify consumers in the event of a security breach.
http://www.dmnews.com/cms/dm-news/legal-privacy/39740.html
I'm not adverse to the bills actually, what I am adverse to is "How would I know
with an ofBiz installation that I've had a breach?"
I don't want the FBI coming after me because I failed to notify the Secret
Service because someone downloaded 10,001 names from our system.
In the case of the recent ecommerce gap, say on a live system, does anyone have
some sort of trip wires that would tell them that someone is scraping data
they shouldn't? And more importantly, unusual requests that just look suspicious?
--
Walter