Interview • 01.03.2013

Online Shops: Secure Shopping Satisfies Customers

Interview with Sebastian Spooren, Project Leader at it-sicherheit.de

Sebastian Spooren: Certifications such as Trusted Shops or the TÜV quality...
Sebastian Spooren: 'Certifications such as Trusted Shops or the TÜV quality seal are the right way to achieve standardized and appropriate security for online shops.'

Whether it’s food, books or electrical appliances – online shops offer a very large assortment of products. At this point, Internet users in Germany are making 25 percent of purchases online. But is online shopping always secure? Online businesses and users should observe several rules when it comes to security.

Sebastian Spooren, Project Leader at it-sicherheit.de, reveals some useful tips at iXtenso about data protection and conveying trustworthiness of online shops to online customers.

Mr. Spooren, to ensure the protection of customer and company information, online businesses have to observe several safety regulations. Which of these are most important?


What is important is that sensitive customer data such as login data or account information is safely stored and adequately protected from third-party access. To prevent this, the online shop has to be regularly audited by independent IT safety experts during security audits. During these audits so-called Web penetration and intrusion detection tests are performed, which check the Web application for weak spots and bottlenecks. This may sometimes uncover several weak spots, starting with SQL injections all the way to critical weak spots in the applied services of the Web application due to outdated versions. Due to insufficient security measures, time and again customer and user information, respectively, are unintentionally made public. To limit the damage potential for the affected party, online businesses should never save user passwords in clear text, but should use so-called hash functions in conjunction with a private key (salted passwords) instead.

In addition, you need to make sure that sensitive data such as order details and payment information are exchanged securely and therefore encrypted between customer and shop owner. Otherwise, outside parties could read sensitive data. Online shoppers should therefore always make sure that sensitive information is exchanged with SSL. The online shopper is able to detect this by the “https” instead of the “http” in the Web browser’s address bar. These days, most online businesses use “https“ for secure communication, but unfortunately encryption is switched on too late in many businesses. The “https” has to be in the browser’s address bar already when you enter sensitive information such as login or registration form for example.

What criteria can convince customers about purchase security?

A customer is not able to discern whether an online shop has put adequate safety measures in place. The layperson can only look after a few security features. Outwardly visible characteristics such as the exchange of sensitive data via “https“ are easy to spot and should be met in any case. There are other options for the experienced user to examine the security of an online shop more closely by calling up the current version of the used Web service, if possible. However, whether the business has internally made adequate provisions to protect account information from third-party access for example is not clear to the user. Many online shops use seals of approval in this case to suggest enough security attention to the user. Generally, the user is not able to assess the authenticity and quality of such seals. To get a better idea of the online store, he/she should refer to experiences and reviews by other users.

What role do certifications by inspection agencies such as Trusted Shops or TÜV (Technical Inspection Authority) play?

Certifications such as Trusted Shops or the TÜV quality seal are the right way to achieve standardized and appropriate security for online shops. There is no such thing as 100% security, and the issuers of such seals can also not attest it. Oftentimes only spot checks are made before the seal of approval is being issued. Proper security is therefore not always guaranteed. In addition, one should keep in mind that the certification authority deemed the shop secure at the time of the inspection. Yet online shops usually continue to work on improvements, input updates and in doing so also possibly and unknowingly weaken the security level of the store as is shown by the example of online bookstore Libri.de. Despite the TÜV seal, after a later software update, approximately 500,000 online customer invoices could be viewed.

Online shops are often at risk from external hacker attacks. How can you protect yourself?

Aside from regular penetration tests where impartial IT security experts rate the security, regular security updates are important. The Institute for Internet Security has developed the free “securityNews“ app for this purpose, which automatically suggests security updates. Above all, the development team as well as the service staff of the online shop should be regularly sensitized on the subject of IT security. This can be implemented with presentations, pamphlets or graphic live hackings. In the latter case, company employees are shown how hackers proceed and how you can protect yourself against it. Find more information on the subject of live hacking at www.internet-sicherheit.de.

Interview conducted by Michalina Chrzanowska; iXtenso.com
First publication on EuroCIS.com

related articles:

popular articles:

Thumbnail-Photo: Smart working in retail: are headsets the solution?...
27.03.2024   #brick and mortar retail #video surveillance

Smart working in retail: are headsets the solution?

Internal communication technology and its potential

Retailers are often faced with the dilemma of combining customer service with operational efficiency. In this intersection ...

Thumbnail-Photo: Zebra: Using transparency to combat losses and shrinkage...
24.05.2024   #Tech in Retail #personnel management

Zebra: Using transparency to combat losses and shrinkage

Companies in the retail sector like Lowes Food, Belk’s and Vera Bradley are gearing themselves up for the future with cost optimisation strategies.

Loss prevention is playing an increasingly important role in reducing inventory discrepancies.Inventory is a major challenge for companies in the retail sector: 82% of retailers in Zebra's latest 16th Annual Global Shopper Study say that ...

Thumbnail-Photo: Record numbers for ITL at EuroCIS retail show in Düsseldorf...
07.03.2024   #self-checkout systems #POS software

Record numbers for ITL at EuroCIS retail show in Düsseldorf

Innovative Technology (ITL) reported a successful EuroCIS in Düsseldorf last week, where the organisers announced record visitor numbers. EuroCIS provides an exclusive hotspot for Retail Technology in Europe, ...

Thumbnail-Photo: How efficient is your workforce management?
24.04.2024   #workforce deployment #workforce management

How efficient is your workforce management?

Workforce management software in retail is successful when it optimizes processes, increases employee satisfaction, and improves ...

Thumbnail-Photo: SES-imagotag becomes VusionGroup
29.01.2024   #software applications #artificial intelligence

SES-imagotag becomes VusionGroup

A new identity highlighting the broader portfolio of innovative solutions
developed by the Group to solve the major challenges of physical commerce

SES-imagotag (Euronext: SESL, FR0010282822), the global leader in digital solutions for physical commerce, today announced that it has changed its name to VusionGroup. This new name embodies the various product lines and solutions that have enhanced ...

Thumbnail-Photo: Intertraffic Amsterdam exhibits ITL innovations ideal for the transport...
02.04.2024   #artificial intelligence #cash handling systems

Intertraffic Amsterdam exhibits ITL innovations ideal for the transport sector

Innovative Technology Ltd (ITL) are set to demo their cash handling and AI powered biometric products to the parking ...

Thumbnail-Photo: The SALTO WECOSYSTEM: A new brand DNA for the future of advanced access...
13.02.2024   #Tech in Retail #access control

The SALTO WECOSYSTEM: A new brand DNA for the future of advanced access

The SALTO WECOSYSTEM embodies the commitment to innovation of each SALTO company and demonstrates ...

Thumbnail-Photo: POCOs experience: efficiency and customer proximity through digital...
30.04.2024   #customer satisfaction #digitization

POCO's experience: efficiency and customer proximity through digital price tags?

How ESL and other digital elements are used in furniture stores

POCO Einrichtungsmärkte GmbH relies on Electronic Shelf Labels (ESL). So far, 93 of the 127 stores have been equipped with this technology ...

Thumbnail-Photo: EuroCIS Germany next stop for ITL’s cash handling and age verification...
13.02.2024   #Tech in Retail #artificial intelligence

EuroCIS Germany next stop for ITL’s cash handling and age verification solutions

Innovative Technology Ltd (ITL) will be joining retail suppliers and industry professionals at ‘EuroShop 2024 – the leading trade fair for retail technology’ which takes place in Düsseldorf, Germany from ...

Thumbnail-Photo: New digital customer experience on the sales floor...
29.04.2024   #digital signage #data warehouse management

New digital customer experience on the sales floor

Connecting stationary retail through omnichannel digital signage

The dynamics of digital change and the fast pace of customer expectations are increasing ...

Supplier

REMIRA Group GmbH
REMIRA Group GmbH
Phoenixplatz 2
44263 Dortmund
Innovative Technology Ltd.
Innovative Technology Ltd.
Innovative Business Park
OL1 4EQ Oldham
SALTO Systems GmbH
SALTO Systems GmbH
Schwelmer Str. 245
42389 Wuppertal
VusionGroup SA
VusionGroup SA
55 place Nelson Mandela
90000 Nanterre
Zebra Technologies Germany GmbH
Zebra Technologies Germany GmbH
Ernst-Dietrich-Platz 2
40882 Ratingen