Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win


Mitigations for tagging & aggregator sites to our site

Posted on 2016-08-04
Medium Priority
Last Modified: 2016-09-25

Any security risks comments on the above 'aggregator' sites will be much appreciated.

Also, Credit Cards customers will be directed from above sites to our secure webpage:
what are the precautions to watch out for?  Any possibility of MITMA (but they are
using ssl ie https, so already mitigated against MITM?) or spoofed redirects to our page?

We are getting external provider to do 'tagging': the external vendor will
 1.  implement tagging on above 4 sites to track the no. of leads directed : 1st tag
 2.  implement tagging at our secure site to track the no. of leads directed: 2nd tag
 3.  implement tagging at our secure site to track the no. of leads directed:  3rd tag
No passwords/credit card/PII info will be stored in above tags, what other precautions
or mitigations we have to watch out for/put in place in the above process or how
do we assess the tags & the tagging process?

Is it crucial to have WAF at our secure site prior to implementing the above & tagging?
Is there any specific IPS signature/filter & secure coding to put in place (in case it is
prone to XSS & injections) ?

I heard in our case, the tags used are likely to be javascripts.


Above link lists some risks, so  I'll need to know if the tagging we are going to implement with
respect to the four aggregators sites will have the following issues & how to mitigate them:

•Control and Ownership: When a site owner puts third-party code on their site, control over the data collection process is ceded to the third-party provider. The more tags, the more third parties with control over the site owner’s data.

•Privacy: Multiple tags on a website put privacy at risk because third parties have access to the data collected on the site (see Control and Ownership above). Also, many brands must adapt their sites to comply with privacy regulation across markets and geographies which becomes increasingly difficult when data collection is in the hands of third parties.

•Data loss: Sometimes tags fail to fire. For every failed tag, data is not collected and revenue opportunities may be lost.

•Piggybacking: It is possible for tags to be chained together through a process called “piggybacking.” This enables tags to be appended to existing tags already in place on the website without making any changes to the page code. Piggybacking can add dozens of tags to a site and introduce services that the site owner may not be aware are on the site. Read more about the history of tags, tag containers and piggybacking on the “History of Tags” page of our website. Control and Ownership: When a site owner puts third-party code on their site, control over the data collection process is ceded to the third-party provider. The more tags, the more third parties with control over the site owner’s data.
Question by:sunhux
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
LVL 12

Expert Comment

by:William Nettmann
ID: 41745371
Wow, you certainly want a lot of free consulting! I would suggest a Gig, but you have indicated that wouldn't be acceptable.

Would you be prepared to do all the research and reporting to answer all of those questions for a small piece of a tee-shirt?

Author Comment

ID: 41745381
EE first started free, then it went to about US$10 per month & now more, so it's not exactly free
LVL 12

Accepted Solution

William Nettmann earned 500 total points
ID: 41745396
That may well be, but please understand that the people answering the questions do not get paid - we get the occasional free tee-shirt.

If you answer a few questions and earn 3000 points a month, you will have free access to ask as many questions as you need to - I guess that is where the idea of Experts EXCHANGE comes in, it is a platform for exchanging information.

I am seriously considering giving up being an "expert" on EE because so many people see me as a free resource, and when people don't pay for something, they consider it worthless - and I do not believe I am worthless, and I am sure worth more than a free tee-shirt now and again.

If you attach any value to the answers to your questions (and you have a whole lot of them in this post) - you should be prepared to pay a bit for them, either by answering other people's questions, or offering a few hundred dollars for someone to do the research and write a report as a Gig.

If the question meets any of the criteria below, recommend it be posted as a project in Gigs:

The asker does not have the skills to carry out the solution provided
The asker prefers that someone else carry out the work
The question can only be solved by remotely accessing a machine
The question requires several hours of work which you can’t do for free

This " requires several hours of work which you can’t do for free".
LVL 111

Assisted Solution

by:Ray Paseur
Ray Paseur earned 500 total points
ID: 41745591
I recommend Gigs.  I see from the question that you have ruled that out, and I urge you to reconsider!

Featured Post

Q2 2017 - Latest Malware & Internet Attacks

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out our latest Quarterly Internet Security Report!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Sometimes Administrators rights are not enough. These cases call for the SYSTEM account. The process in this article outlines the steps required to execute commands using the SYSTEM account.
An overview of cyber security, cyber crime, and personal protection against hackers. Includes a brief summary of the Equifax breach and why everyone should be aware of it. Other subjects include: how cyber security has failed to advance with technol…
The viewer will learn how to look for a specific file type in a local or remote server directory using PHP.
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

618 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question