If/when I hire a web developer to build my site (most likey someone abroad), are
there any security concerns I should keep in mind before granting them access to
my site?
I could be going off the deep end here, but since I'll be accepting payments
through my site is it possible a malicious web developer could install something
that could intercept/reroute payments to them?
Any precautions to take before granting someone access?
Thank you!
Originally posted by Shane Frazier on Facebook
link: facebook.com/groups/2209390642/user/100001284000699/
there any security concerns I should keep in mind before granting them access to
my site?
I could be going off the deep end here, but since I'll be accepting payments
through my site is it possible a malicious web developer could install something
that could intercept/reroute payments to them?
Any precautions to take before granting someone access?
Thank you!
Originally posted by Shane Frazier on Facebook
link: facebook.com/groups/2209390642/user/100001284000699/
establish your concerns with your web developer. A lot of times when I'm working
with clients who have interesting payment methods, that banking info or banking
representatives are involved (many of times, those sites have to be PCI
compliant), I assure my client that I don't share their information with anyone
and even hand them education on keeping their information secure and further
steps to ensure, after working with me, to change any of their passwords to any
sensitive information.
Always have a contract (and even NDA, if you believe you should require it for
your project) if you are giving really sensitive information. Always make sure
the web developer provides a proposal that aside from scope, has policies on
what to expect from them, and what to expect from you, and what happens when
things may go sideways. Make sure to read and request to add anything where need
be, if security isn't mentioned.
Additionally make sure as part of scope, a secure solution is proposed, if your
site doesn't already have one in place. Lastly, if you have a payment gateway
that requires PCI compliance, make sure your developer knows how to do that.