Much of this will depend on how you deploy OFBiz, ie the underlying software like operating systems and databases that it is running on, and to some extend the application server as well.

For OFBiz itself we don't have any trip-wires, and in fact unless you have a specific vulnerability in mind trip-wires in any system don't mean much.

What we do have in OFBiz is Visitor, Visit and ServerHit tracking. This allows you to see who did what and when.

-David


On Feb 5, 2007, at 9:52 AM, Walter Vaughan wrote:

The recently discovered/fixed gap in ecommerce security got me wondering about an article I just read. Sen. Dianne Feinstein is re- introducing a bill that is supported by the United States Direct Marketing Association that would require businesses to notify consumers in the event of a security breach.

http://www.dmnews.com/cms/dm-news/legal-privacy/39740.html

I'm not adverse to the bills actually, what I am adverse to is "How would I know with an ofBiz installation that I've had a breach?"

I don't want the FBI coming after me because I failed to notify the Secret Service because someone downloaded 10,001 names from our system.

In the case of the recent ecommerce gap, say on a live system, does anyone have some sort of trip wires that would tell them that someone is scraping data they shouldn't? And more importantly, unusual requests that just look suspicious?

--
Walter


Attachment: smime.p7s
Description: S/MIME cryptographic signature

Reply via email to