View Poll Results: How much more are you willing to pay for improved security in vbseo?

Voters
1. You may not vote on this poll
  • I am not willing to pay more and I am willing to accept the risk

    0 0%
  • $10 more

    0 0%
  • $20 more

    0 0%
  • $30 more

    0 0%
  • $40 more

    0 0%
  • $50 more

    0 0%
  • $60 more

    0 0%
  • $70 more

    0 0%
  • $80 more

    0 0%
  • $100 more

    1 100.00%
Results 1 to 3 of 3
Like Tree2Likes
  • 1 Post By Brian Cummiskey

Would you be willing to pay more for vbseo for improved security?

This is a discussion on Would you be willing to pay more for vbseo for improved security? within the General Discussion forums, part of the vBSEO SEO Plugin category; First of all, I wanted to say this post is not intended to be a rant or overly negative. Just ...

  1. #1
    Member
    Real Name
    m0rgulvale
    Join Date
    May 2009
    Posts
    88
    Liked
    2 times

    Would you be willing to pay more for vbseo for improved security?

    First of all, I wanted to say this post is not intended to be a rant or overly negative. Just realistic about risk.

    My background is in IT security, software engineering, and network engineering and likewise I am very concerned about any system or Web application with vulnerabilities. Nobody is perfect including me and and any software developers. To err is human.

    The positives:
    vbseo is a really great product that has had really positives results for my site overall. The vbseo team does notify customers about vulnerabilities quickly most of the time. I have great respect for the vbseo team.

    The negatives:
    vbseo has had some pretty bad security flaws. Anyone using the Internet can do some research on these and find out what specifically. These flaws do pose a risk to any business using vbseo. When a serious flaw is announced, I ask myself "what might have happened during the last 3 months as a result of this just announced vulnerability?" I ask myself what vulnerability will be next. I don't want to have to worry about this. I find myself in a bind. Yes vbseo helps search rankings, but the fact is there is increased security risk with using this product. And the fact is one exploited vulnerability could cause serious harm to a company or possibly put someone out of business.

    My perspective:

    I come from the banking industry where my company had absolutely zero tolerance for security flaws in our web apps. We invested in automated vulnerability scanning tools like WhiteHat which were extremely valuable. We had security metrics which measured vulnerabilities by programmer per week. People had incentives to write secure code.

    So what should be done? I think vbseo needs to hire a programmer to focus only on security and nothing else at all. I would easily be willing to pay $100 more for this. I need to have some comfort going to sleep at night that there isn't some random flaw in vbseo that could result in my site being hacked. I don't want to have to wake up at 8AM before work to patch VBSEO. I don't want to have to worry about these vulnerabilities. They need to stop.

    Other options: use an automated vulnerability scanning tool like WhiteHat. Do something to reduce the likelihood of flaws. Have yearly training budget for security training for coders.

    I am not expecting security to ever be "perfect" but it needs improvement here. I don't care at all about new features in vbseo. It means nothing to me if the product is not secure. Focus 95% on security and 5% on new features. This product "works". Nothing else is needed. Make it secure. Nothing else. I need to be able to sit back and relax knowing it is secure. One thing I expect to be perfect is *never* a SQL injection flaw. Input validation and parameterized functions will prevent this.


    As a business owner I value data integrity, confidentiality, and availability, and these flaws pose a risk to all of them. Although the product does help with search results.

    I am not trying to make anyone look "bad". I am just trying to help.


    Best Regards,

    m0rgulvale

  2. #2
    vBSEO Staff Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,789
    Liked
    657 times
    Blog Entries
    2
    We at vBSEO do take security very seriously. We always attempt to release the most secure software possible with every release. All changes are reviewed by at least 3 development staff members for code QA prior to every release.

    Hackers are very creative people. They think of things that honestly don't even make sense to a programmer and sometimes find a hole in one of the many layers involved in the network, the server, the core software/os, the scripts and/or the db on the server itself.

    Staying on the latest release is always the best thing to do as it gives hackers the least amount of time with 'having' the software. In this particular case as well, the latest release, 3.6.0, was not effected.

    To the topic at hand, bringing on a new team member for the sole purpose of security investigation is not in our budget right now. From a customer point of view, while many are big board owners making a profit, the vast majority of our customer base run 'medium' sized sites and make make a few bucks here and there. But the cost of the software going up $100 in most cases would put that completely out of their budget, rivaling the cost of vb itself at $250.. To pay a code security expert, that person would demand at least $80-100k USD salary. Can we get 10,000 people to spend an extra $100 a year with us for security purposes alone? Maybe, but it would need to be thought out. And what happens when that person misses something? Everyone who paid more for this will revolt over paying for it and like you said, no one is perfect.

    It is nearly impossible to make 100% exploit/bug free software when it is designed to run on 1000s of combinations of servers, platforms, vb versions, php versions, and all the rest once you get beyond a 'Hello World' echo. Most of the 'bigger' issues that were reported stemmed from people leaving their config files or other files/folders writable. This isn't a code issue. We released a version shortly there after that included better htacces files in directories and put a banner notice about writable files but the core issue was not with the codebase. No matter how much we QA and print directions, there are people that can't/won't/didn't follow the directions correctly. Even the old versions of vbseo 3.x series has a note about locking down the config file via chmod when settings are done and so forth.

    We purchased and ran McCafe Secure (used to be called HackerSafe) in the past. We found it basically useless as it only tested the most basic form post and cookie events. Had we been running currently, it likely would not have reported the exploit that was patched in the 3.5.2 update either due to the inventive way the exploit was run.

    Reporting piracy will also help stop security issues. If they can't obtain the software in the first place, they will have a harder time hacking it. and if they do pay for it and get a license, we may be able to stop them because we have their information on record. Unfortunately, paying customers keep submitting their personal paid software to warez sites and groups. We ban and remove them as customers we find them, but it's an on-going effort and blocking it completely will likely never happen.
    Report Piracy

    We appreciate your concerns and I assure you that we always do all that we can without being able to predict the future for every release with the very competent team that we have in place here now.

  3. #3
    Member
    Real Name
    m0rgulvale
    Join Date
    May 2009
    Posts
    88
    Liked
    2 times
    thx for the reply Brian. i know u guys care and that matter a lot b/c lots of companies dont care at all about security stuff

    keep up the great work overall

    hopefully other ppl would be willing to pay more too.

    take care
    peace
    -M0rgulvale

Similar Threads

  1. New/improved domain name - Should I forward? How?
    By Amin Sabet in forum General Discussion
    Replies: 2
    Last Post: 03-10-2011, 01:19 PM
  2. [Video] Matt Cutts: When will the data in Webmaster Tools be improved?
    By Michael Biddle in forum General Discussion
    Replies: 0
    Last Post: 07-07-2009, 07:57 PM
  3. Alexa Improved alot
    By UnderEstimated in forum Off-Topic & Chit Chat
    Replies: 8
    Last Post: 04-17-2009, 12:22 PM
  4. [How to] Get the most Security for vBSEO
    By marco1 in forum Member Articles
    Replies: 8
    Last Post: 01-09-2009, 01:23 PM
  5. Replies: 5
    Last Post: 03-20-2008, 10:52 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •