Link to home
Start Free TrialLog in
Avatar of sunhux
sunhux

asked on

Mitigations for tagging & aggregator sites to our site

https://www.gobear.com.sg/
https://get.com/sg/credit-cards/
http://www.moneysmart.sg/credit-cards
https://www.singsaver.com.sg/credit-card/best-deals

Q1:
Any security risks comments on the above 'aggregator' sites will be much appreciated.

Q2:
Also, Credit Cards customers will be directed from above sites to our secure webpage:
what are the precautions to watch out for?  Any possibility of MITMA (but they are
using ssl ie https, so already mitigated against MITM?) or spoofed redirects to our page?

Q3:
We are getting external provider to do 'tagging': the external vendor will
 1.  implement tagging on above 4 sites to track the no. of leads directed : 1st tag
 2.  implement tagging at our secure site to track the no. of leads directed: 2nd tag
 3.  implement tagging at our secure site to track the no. of leads directed:  3rd tag
No passwords/credit card/PII info will be stored in above tags, what other precautions
or mitigations we have to watch out for/put in place in the above process or how
do we assess the tags & the tagging process?

Q4:
Is it crucial to have WAF at our secure site prior to implementing the above & tagging?
Is there any specific IPS signature/filter & secure coding to put in place (in case it is
prone to XSS & injections) ?

I heard in our case, the tags used are likely to be javascripts.


http://www.signal.co/resources/tag-management-101/

Above link lists some risks, so  I'll need to know if the tagging we are going to implement with
respect to the four aggregators sites will have the following issues & how to mitigate them:

•Control and Ownership: When a site owner puts third-party code on their site, control over the data collection process is ceded to the third-party provider. The more tags, the more third parties with control over the site owner’s data.

•Privacy: Multiple tags on a website put privacy at risk because third parties have access to the data collected on the site (see Control and Ownership above). Also, many brands must adapt their sites to comply with privacy regulation across markets and geographies which becomes increasingly difficult when data collection is in the hands of third parties.

•Data loss: Sometimes tags fail to fire. For every failed tag, data is not collected and revenue opportunities may be lost.

•Piggybacking: It is possible for tags to be chained together through a process called “piggybacking.” This enables tags to be appended to existing tags already in place on the website without making any changes to the page code. Piggybacking can add dozens of tags to a site and introduce services that the site owner may not be aware are on the site. Read more about the history of tags, tag containers and piggybacking on the “History of Tags” page of our website. Control and Ownership: When a site owner puts third-party code on their site, control over the data collection process is ceded to the third-party provider. The more tags, the more third parties with control over the site owner’s data.
Avatar of William Nettmann
William Nettmann
Flag of South Africa image

Wow, you certainly want a lot of free consulting! I would suggest a Gig, but you have indicated that wouldn't be acceptable.

Would you be prepared to do all the research and reporting to answer all of those questions for a small piece of a tee-shirt?
Avatar of sunhux
sunhux

ASKER

EE first started free, then it went to about US$10 per month & now more, so it's not exactly free
ASKER CERTIFIED SOLUTION
Avatar of William Nettmann
William Nettmann
Flag of South Africa image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial