In episode 15 of Do the Woo, a podcast for WooCommerce shop owners, Bob Dunn, also known as BobWP, discusses the importance of website security with Neill Feather, president of SiteLock.
They discuss the misconceptions about WordPress security, the importance of malware scans, and the benefits of web application firewalls. Neill emphasizes the importance of strong, frequently changed passwords and two-factor authentication for website security.
He also discusses the role of hosting providers in website security, and the importance of SSL for all sites, especially e-commerce sites. The episode concludes with a discussion on the frustrations of online shopping and the items they prefer to buy in person.
Episode Transcript
BobWP:
Hey everyone, and welcome to episode 15 of Do the Woo, A podcast for WooCommerce shop owners, Bob Dunn here, also known as Bob WP on the web. Today we are talking about one of the most critical pieces for your online store, but in reality just as important to any website, and that is security. As you know, WordPress back in the earlier days was getting a bad rap for being vulnerable to hacks, but in reality there were a lot of other variables in play there that one cannot blame on WordPress core, but rather other issues around your site. So security is certainly a hot button in any case, and that is why we are talking to Neill Feather, president of SiteLock, who also happens to be our sponsor. Welcome to the show, Neill.
Neill:
Thanks, Bob. Thanks for having me.
BobWP:
You bet. Now what I’m loving about today’s show is that we’re not only learning what SiteLock can do for your site, but as Neil tells us more about that, we are going to dive into a lot of what he describes as SiteLock features and not just learn about the how around security, but also the why, which is my mantra as I’ve trained over the years. A lot of terms can be thrown around when it comes to security, and we have Neil here to tell us exactly why those are important to your site’s health. Let’s start by having you tell us a little bit about yourself and what SiteLock can do for us.
Neill:
Sure. Thanks again, Bob. As far as my background goes, I’ve been working in IT and development since I was probably 12 years old. I had my first job writing code in junior high and since then moved along throughout my career in various different jobs all around harnessing the power of large data sets and what you can glean from having access to a lot of data. And that’s one of the themes that we have here at SiteLock. We started the company in 2008 with the idea that securing your website should be easy for anyone to do, particularly for sure e-commerce owners, but any website owner, whether they’re a large business or a small company. And we wanted to make products that were accessible, affordable, understandable to small and medium sized businesses, and we started doing that back in 2008. Fast forward now we have a suite of products that help business owners do that.
We think it’s so important to work with these website owners. We have about 6 million websites that are active right now using the products, which bringing it back to that data point really gives us access to a lot of new threat information, new malware information that we’re able to turn around so that our customers are the first to know when something is happening with their website and we can help them react to that and help them avoid any kind of potential negative consequences that may come with security issues on their site. So given the reality of today that security issues are out there and unfortunately affect a lot of websites, we feel like we’re well positioned and we want to be there as that trusted source for our customers. And being there for us means twenty four seven support, phone support and being available whenever it’s on the customer’s schedule, not on our schedule.
BobWP:
Yeah, I’m so huge on security. I mean, I train a lot of users and beginners. That’s what I’ve done in the past, and a lot of them that really gets put down on the priority list until unfortunately the first time they get hacked, no matter how much I can beat it into their head. So it is a constant education process. And I know that you offer a lot of different services, and you had mentioned malware, which everybody freaks out on that word, but I know that malware scans are critical and can you tell us a little bit more about malware scans and then maybe give us some advice on how often your site should be scanned?
Neill:
Yeah, sure. I think everybody’s familiar with malware and viruses as it pertains to their computer, and I think that’s a good kind of analogy to think about your website. But not many people, to your point, kind of think about security and securing their website out of the gate, right? I’m too small, no one would bother me. Why would I need to worry about this? And the fact is that a lot of these cyber criminals aren’t necessarily targeting an individual business. They may be targeting anyone who has access to things they care about, customer data, computing resources, other financial information, email addresses that they can use in other attacks or other future manners to get some kind of financial benefit. So a lot of it is really financially driven and my is one of the tools that they use to benefit themselves financially. Now, malware can take many different forms, whether it be literally trying to steal data out of your database or even something where they’re just using your server to launch an attack against another website.
You have a lot of computing resources at your disposal when you’re hosting a website. So they’re able to use those to send spam emails using your account to your trusted customers and those kinds of things so that they can then monetize those later on. So you want to be looking for that malware so that you’re aware of when it comes on your site. We would recommend that you scan it, at least you want to look for it daily. At SiteLock, we offer products like SiteLock, infinity that scan continuously. It really never stops looking for malware within your code. So you’re getting that kind of real time data. If you’re a business owner that is really concerned about this kind of thing, that’s something that you may want to move to is pretty much real time monitoring behind the scenes for malware. So I think with any security piece, it comes down to risk and trade-offs that you’re willing to make. And we think that as frequently as you can is great because we want to minimize that risk. But if you’re a little bit less risk averse and maybe just starting out, you may want to just scale that down and look at it once a month or be checking Google safe browsing and some of the other tools that are available for you to check proactively rather than having something run automatically our products that would do.
BobWP:
Yeah, I always recommend, I know I have for clients, the reason I like automatic is most of these people that are running these sites barely have enough time to keep things updated and stuff, and it’s just another thing on their little list. It’s like go and scan your site. Well, that often gets again, oh, well I’ll do that later. Oh, now I’m going out. Don’t have time for that. So I do like the auto scanning. I do encourage to use services like you just because people don’t have the time, even though in a perfect world we would.
Neill:
Yeah, I think that’s the trick, right? Security occupies a very small portion of people’s overall mind share until it’s everything for if you suffer a breach or something. But for the most part, people aren’t really thinking about it. So to your point, we recommend automation to the extent you possibly can, even where we automate not only the identification of malware for customers, but also the removal of it. So they don’t ever have to worry about it calling us, sending us the support ticket if they want it to be hands off, we can make it as hands off as it needs to be. And to your point, look, most business owners are not passionate about security for their website. We are. We’re nerds. We live and breathe this stuff, but for the most part, most of our customers don’t understand it, don’t want to understand it, and just want to get back to whatever their business is because what they’re passionate about. So we think that we have a role in managing the security and let them do what they do to drive the growth of their small businesses.
BobWP:
Exactly, yeah. It’s security, maintenance, those are the things they really don’t want to do, they don’t want to be bothered with and they should get it in place. So that makes a very good point. Kind of on the same scale, maybe protecting, one of the things that I know that you offer is web application firewalls. And I know that I’ve talked to some people and they kind of get it because I think of maybe their internet, their ISP and stuff, but they still, it’s like firewalls and they may feel like, is this something I’m putting on here or is somebody actually watching my site? It’s very confusing to them, and I would love to hear your explanation of what a firewall is and how they can benefit from it, what it really does.
Neill:
Yeah, sure. I think it’s an area that definitely causes some confusion for folks because firewalls get thrown around in a lot of different contexts. You have a firewall on a personal firewall on your computer. If you have Windows computer, you have a firewall at your router. If you’re running your own servers, you have a firewall there. So a lot of customers, we talk to ’em about web application firewalls and they say, oh, we have that. I have that through Microsoft, or I use the IP tables on. This is more technical guys, but when you think about firewalls for your computer or your network or what have you, a lot of that is based around determining who should be allowed in and who should not be allowed in. And it is relatively straightforward because you don’t want anyone coming in who’s not an employee or authenticated in some other way, especially to your computer if you didn’t ask for it.
Don’t give it to me basically is the rule, right? Your website is a different kind of animal because you really want people to come to your website. You don’t know where they’re going to come from necessarily. You don’t know what tools they’re going to use to access your website if it’s a mobile browser or a desktop browser if they’re using tour. Some other kind of means to access your site, but you want everyone there because you want to attract as many customers to your shop and drive as much conversion as you possibly can. So when you think about a web application firewall, it has to do a little bit more detailed review of who’s coming to your site and what they’re doing when they come there. So what it’s doing is it’s looking at the information that’s being sent from the visitor to your website and is trying to make a determination about what that visitor’s intent is based on all the information they can gather about that request, where it’s coming from, what tools they’re using, what information’s being sent in the request.
And then based on that, it’ll either allow the customer to come through or block that visitor from coming through. And so it is a pretty sophisticated way to block malicious traffic to your site because what you want is all your customers to come to your site, and you don’t want people to be attacking your site, trying to extract data out of your database or trick your customers into giving them information, their passwords and things like that. So the web application firewall is there to evaluate traffic to the website specifically and has very sophisticated kind of rule sets that will determine who’s there for good and who’s there for bad essentially, and try to block out those folks who are there for malicious purposes while letting through the normal users.
BobWP:
So it’s really kind of a customized approach that the firewalls figure out.
Neill:
Exactly. So in a very simple case, it is trying to block a lot of automated traffic to your site that hackers use to find maybe a vulnerable WordPress plugin or a vulnerable piece of code that is widely distributed across the internet, and that’s like an automated kind of attack. And those are probably the easiest thing to stop because you can kind of see what a machine looks like when it comes to a website versus a human. When you start talking about human-based attacks where I sit down and try to attack your site specifically more of a targeted attack, that becomes much more difficult to block and requires a little more sophistication in terms of how you do that so that you’re not blocking real users, but you’re letting them through and still blocking out the malicious guys. And there are a lot of tools where website owners can do that for themselves, but it takes quite a bit of technical wherewithal and constant maintenance.
To your point about maintenance, before that, nobody really wants to do maintenance. Running your own web application firewall takes quite a bit of maintenance, but there are tools out there and we offer one called TruShield that will help kind of take that burden off and manage that for you as a customer. There are many tools that will do it. We feel like ours is the best because it’s very well able to discern good from bad and doesn’t block out your real users in an attempt to stop the malicious traffic. It has a very low, what we call false positive rate.
BobWP:
I’m all for paying somebody to take care of this stuff. I I like the explanation, I love your explanation, and I’ve learned some myself from that explanation, but I don’t want to deal with it. I want somebody else to,
Neill:
Exactly. Yeah, I think that’s true for most folks. If you’re a developer or you get excited about this stuff, that’s one thing. But if you are running an e-commerce shop to sell apparel or cupcakes or something like that, where is this on your radar? It’s not really something you want to think about.
BobWP:
Oh, not at all. Nope. That kind of brings me into the hosting aspect of it. I know that there’s manage hosting out there now, WordPress manage hosting that has extra security, they put it in place and then you got shared hosting, you got all the different hosting. Is there some way for somebody, I mean, everybody’s going to say we provide some kind of security. I mean that’s just going to be a no brainer because if it looked bad, if they didn’t, how can someone evaluate if the hosting they’re using is providing enough security or is that too tough to evaluate as a user?
Neill:
I think as an average user, it’s going to be a little tricky, but there are some things you can definitely look for. Is your hosting provider talking about security on their site? Is it prominent? Do they work with people who provide specialized tools for web application security a lot? We work with a lot of hosts to help provide those tools for them, and you can kind of see where their focus level is on security by looking for some kind of tells like that. If we’re playing poker, you’d be able to tell that they care by looking for stuff like that. The other thing kind of like that is do they let you use password one as your hosting control panel password? If they’re even letting you make those kinds of decisions, you can kind of tell what the security posture looks like. So I think that there are things like that that you can look for.
The other thing I would say is ask them, see what their answer is. And if it’s an answer that is satisfactory and has a lot of specific detail in it and they can send you information about it, then you kind of build that confidence in it. But as far as assessing individual tools and technologies, I think that’s going to be difficult for the typical business owner to work on. But those are some of the things that you can kind of zero in on that might help you determine one from the other. And by and large, the hosting community does a very, very good job with the security of their infrastructure. What they’re not necessarily always doing, unless you’re getting into kind of a design and managed kind of world, is securing your individual website. And that’s where a lot of them will offer tools like ours to help you with that. If you think about it for a minute, if they weren’t doing a very good job securing the infrastructure, especially some of these large players, there would be a lot more mass breaches that you’d read about where millions of sites were taken offline in a day. So I think when you’re working with, especially some of the bigger hosts, most of the concern is how do I secure my website versus how are they securing the overall environment, which I think most of them, as I said, do a pretty good job of doing.
BobWP:
Yeah, I think that I had asked somebody in security a while back and they had said almost that exact same thing, that typically most of the time when a site is hacked, it’s more the individual’s responsibility than the host. The host is more concerned about their servers. They’re not going to be spending time and making sure you update everything and that all your plugins are update and you’re not using password for password and all that good stuff.
Neill:
Yeah, I mean you wouldn’t want them to, right? So how much control do you want to give them over your website contents, right? You want to control that and you want to own it. So they kind of give you pretty good license within your environment. We often use the analogy of if you live in an apartment building, your landlord, in this case the hosting company is going to provide security for the lobby and for the common areas and things like that, not letting just anyone into the building. But if you leave the door to your apartment open and somebody comes in and steals your TV and walks out, that’s on you. So just like in your website hosting world, you have your kind of directory, your folder, your area. If it’s a VPs, you have your sliver of that server, you’ve got responsibility for that part, and they’re taking responsibility for the building, if you will, or the server that you’re on.
BobWP:
Yeah, I’m going to steal that analogy. I love that one. That’s good. That really is straightforward. Okay, so now we’ve been talking how important security is for websites obviously so far now with e-commerce sites, it’s obviously just as important and it might be more. Where do you see the biggest weaknesses in a lot of the sites you’ve actually taken over or work with when it comes to e-commerce and online shops?
Neill:
I think it’s not all that different from ordinary sites. I think, yeah, to your point, I think folks are a little bit more aware of some of the basic security measures like SSL and things like that because they’re used to processing payments and handling credit card information. But some of the same things that we see across the board are failing to update key software components in your shopping cart software or in your e-commerce store and using weak or repetitive passwords. And let me explain what I mean. So if you have a LinkedIn account, your password is in some hacker’s database right now, right? If you didn’t update it in the last year, so if you’re using that same password to control your e-commerce store, there’s a very good chance that someone’s going to be breaking into that in the not too distant future. And so we think about using different passwords, you may have a strong password that you use for everything, and that was good enough until some of these large online locations started getting compromised and people were taking big chunks of passwords and just trying all of them username and password combinations on various different sites.
So I think that using different passwords, and one of the things that we advocate for customers as well is adding a second factor of authentication to where even after you type in your password, it’ll text your phone and then you have to type in another code in order to actually get access to a privileged area, an admin area of the website if you will. So that gives you a lot more control to if your password does happen to get compromised, someone also has to have stolen your phone, which is fairly unlikely combination of things to have happened.
BobWP:
Yeah. Do you have your own personal rule of thumb or something you suggest as far as how often you should change your existing passwords?
Neill:
I think if you’re using two-factor authentication, the onus to change passwords is a little bit less. But if you’re not using something like that every 90 days, 60 or 90 days is a pretty good rule of thumb for most folks. That gets to be pretty onerous. So you may want to use a password management tool, and there are a lot of ’em out there to help you out with that if you’re not using two-factor on important things, we offer a one click two factor for WordPress customers to manage in their admin area, so they can just have that two-factor authentication right out of the gate. But if you’re not using something like that, definitely every 60 days or so, and if something that you use gets compromised, I think Marriott got compromised last year, Adobe LinkedIn, if your password’s in there, change all your passwords.
BobWP:
So if you’re freaking out right now, pause the button on this, go change a password, then come back and listen to the rest of it. Okay. Don’t be sitting there worried about it.
Neill:
Yeah, exactly. I think that’s important.
BobWP:
So we’ve talked about everything. You’ve even mentioned SSL, which we know is becoming more and more, and it seems like it’s becoming more and more critical to just about all sites. Is there anything else we haven’t talked about that people should consider, especially around e-commerce sites and security? I know you’ve covered a lot already, but is there anything we quite haven’t touched on?
Neill:
I think one thing that takes no technical ability and is good to do for website owners is just practice good hygiene with your web applications. And what I mean by that is if you’re not using it, get rid of it. So if you have a plugin that you thought might be cool a year ago, but you never used it, get rid of that. If you have an admin who no longer works at your company, remove their user, it’s that kind of stuff that takes five minutes. But you will, when that’s the reason that something you get compromised or data leak or something like that, you’re kicking yourself about it. So I would say practice that good hygiene and take that five minutes a month and look through your list of users and see if they should all be there. Look through your list of plugins and see if they should all be there and if not, get rid of ’em because those are really attractive vectors for people to break into your site.
BobWP:
Yeah, good tips, excellent tips. Now, I know you mentioned customer support. And for me, when I choose a service, customer support is huge. And I know that really any service with whether security or not, you can’t survive without it. And what you need to know is SiteLock is among those services that not only offers industry leading website security solutions, but top-notch customer support. And like he said, 24 7, 365, you can always reach a live person. And I’ll tell you, I’ve even had Maya, I had my site hacked once, and the minute it happens, you’re not going to sit back and go, oh, well, I’m going to finish my dinner, or I’m going to go back into the conference session I was at. No, you run somewhere. You want to get hold of somebody. So that’s why that kind of service is so critical. It’s just another reason why SiteLock is your trusted source for website protection.
And we haven’t mentioned the uur L yet to check them out, but go to sitelock.com/do the woo. Well, these have been excellent tips. I know that people are jotting them down, and if they haven’t, I’m going to tell you re-listen, jot them down, make sure you’re covered. But what I’d like to do at the same time is have our guests, Neil, take off his president hat at SiteLock. And I know that probably when you’re out there doing this stuff, even as a shopper, you are probably thinking security in the back of your head all the time. I mean, we can’t help but do that. But I’m going to say you have just quit for the day. You’re home in the evening. You’re looking for that special something online. And I have a few questions I want to get answers from you regarding you as a shopper. When you get on a site, what is the most frustrating thing as far as an online store that you see again and again and again and it just drives you nuts?
Neill:
My biggest gripe about online shopping is if you tell me you’re going to give me a box to check that says, remember me, you should remember me. The next time I come all too often I find myself having to log back in again in order for it to remember who I am. And then as a security person, I want to have that security, but there are certain things that you can know about me and show me that are personalized without having a security issue in there. And especially if you’re going to tell me you’re going to remember me, then please do it. So that’s my biggest frustration, I guess.
BobWP:
Yeah, I think that’s my wife’s too. She will always say, she’ll be on some site and she’ll say, why is this? Not every time I come here, I tick this box and every time I come back it’s asking me, and we got one password that we use, and she doesn’t really like it. She always has to log into that too, because she seems to always be logged out of that. So I totally get that. Now, I’m not sure how much you buy online, but is there anything that’s available online that you would never buy online, you got to buy in person?
Neill:
That’s a good question. I know there are a lot of really good online grocery buying services, but I like to see the food myself before I buy it. And I’m sure that they’re great, but I’d have a hard time. I think turning it down, if something came through and I didn’t like the produce or whatever, I like to see it myself. So I think that that’s the one thing I’ll always want to go and kind of touch and feel and do myself.
BobWP:
Kind of a crapshoot already when you’re picking out produce on some things, if it’s going to turn out good, now you’ve got to trust them to bring you the ripest fruit or whatever. If you could sell anything you wanted online, if you were able to open up an online store and sell something and you didn’t have to worry about, Hey, if I don’t make much money, it’s no big deal. I am incredibly wealthy at this point in my life. I just want to sell this online. This is going to be fun. Is there something you can think of?
Neill:
If I were incredibly wealthy, I guess I’d sell pictures of myself drinking margaritas on the beach. I think a childhood passion of mine was collected in baseball cards and sports cards in general. So I think that would be a cool thing to dust off and do in my retirement. And using an online kind of venue to do that I think would be cool because you get to talk to a lot of people about something that I always thought was pretty interesting, albeit very, very nerdy.
BobWP:
And I bet it would have incredible security so you wouldn’t be able to hack into this and get his baseball cards or order ’em under a false name. Well, I think we have a great show that’s going to be residing in our archives on security now, and I love what you’ve been able to share with us, stuff that shop owners should be aware of, basically anybody with the website should be aware of. And I want to thank you again, Neil, for giving us those great insights on security.
Neill:
Thank you, Bob. I appreciate it.
BobWP:
And also, I want to thank you and everyone at SiteLock for sponsoring our podcast over the last month. You’re awesome because of that in itself. Don’t forget to visit them at sitelock.com/do the woo and check out all that they offer in making your online store and your website more secure, and in addition, giving you peace of mind. So until our next show, keep those online doors locked from intruders. Make sure your site is happy and healthy, and most of all, don’t forget to.






