Jump to content
thirty bees forum

lesley

Members
  • Posts

    2,223
  • Joined

  • Last visited

  • Days Won

    36

Posts posted by lesley

  1. @datakick The attacks that we were referring to generally require file system access. Like the one mentioned in the article that was posted, I have seen that one on a few prestashop sites. Basically they either upload a malformed paypal module or edit the existing, then point it to a local directory with a fake paypal login page that sends the creds to the hackers email. 

     

    @Briljander its not the easiest thing in the world to set up, but you can use local git or github, with hooks and have an email sent to you when there has been a change. You might be able to accomplish it with a shell script as well, just running every 30 minutes or so, staging files and if there is anything to stage, trigger an email. 

  2. These attacks have been around for years, but they all rely on someone getting file system access. If they have that access they can do anything they want. 

     

    If you are looking for an easy way to be alerted if something happens git could be a good early warning system. You can trigger an email if changes are staged, alerting you to an issue with your site being compromised. 

  3. You are correct on the USPS making a wash, that is the idea at least. But on thing to consider is the ageing fleet that no one wants to deal with. https://www.uspsoig.gov/document/delivery-vehicle-fleet-replacement  Most people do not give it second thought, but those mail trucks that deliver the daily mail are 25 years old. https://about.usps.com/news/statements/011516.htm  Thats pretty old, when you consider they have 190k of them. Something is going to have to be done at some point. 

     

    As far as cheap goods pouring in, its an amazon problem. I am not sure if you saw, but amazon got nailed on a lawsuit about them a couple months ago. Basically it was a fly by night cheap chinese good company that made leashes, someone got their eye poked out with one and amazon does not keep enough records to know who the person should sue, so the court allowed them to sue amazon. As that becomes more common place amazon will either crack down, or just die by lawsuit, so that problem will be handled. 

     

    But granted, I will say, most of my clients don't have to deal with those issues because they manufacture their own products or have their own brands, so they have to deal with brand loyalty issues. 

    • Like 1
  4. I don't think our postal rates are going anywhere, especially considering the state of our postal service, they are liekly to rise again in the next couple years no matter what we do with foreign packages. But at the same time I have not heard any of my US clients be upset over chinese products coming in, but my CA clients are worried about how they will still ship here. 

  5. I have several clients that do this. Some of them do it wrong and some of them do it right. If it were me doing it I would either rely on a sub domain for each store or a / for each store. like store.com/us, store.com/ca. One of those would be the best move.

    Another important consideration is putting people from the right country in the right store. We started using the cloudflare api for that a while back, it is pretty solid on geolocation and is free. @datakick even ended up making a module for it.

     

    The third thing I would do is make sure every store can ship to every location. That reduces the hassle of people traveling and not being able to order. 

    • Like 1
×
×
  • Create New...