CiviCRM Community Forums (archive)

*

News:

Have a question about CiviCRM?
Get it answered quickly at the new
CiviCRM Stack Exchange Q+A site

This forum was archived on 25 November 2017. Learn more.
How to get involved.
What to do if you think you've found a bug.



  • CiviCRM Community Forums (archive) »
  • Old sections (read-only, deprecated) »
  • Support »
  • Pre-installation Questions (Moderator: Dave Greenberg) »
  • Security - CiviCRM if you might get hacked?
Pages: [1]

Author Topic: Security - CiviCRM if you might get hacked?  (Read 934 times)

Starwhale

  • Guest
Security - CiviCRM if you might get hacked?
June 02, 2010, 06:06:26 am

I'm just making plans for a new website for a brand new charity.  I'm tending towards a build in Drupal or Joomla backed up by CiviCRM.

One thing I know my clients will worry about is the security of keeping registrants details on a web hosted site.  I went to a presentation on CiviCRM last night where the answer seemed to be that security doesn't depend on the CiviCRM system itself, but rather what security walls you build around it.  But I wanted to fish about a bit further.

I'd be especially glad if people can point me to charities that are subject to hack attacks and have chosen to use CiviCRM.  And secondly, what questions should I be asking my developer to make sure the system is very secure?

Cheers,

xavier

  • Forum Godess / God
  • I’m (like) Lobo ;)
  • *****
  • Posts: 4453
  • Karma: 161
    • Tech To The People
  • CiviCRM version: yes probably
  • CMS version: drupal
Re: Security - CiviCRM if you might get hacked?
June 02, 2010, 06:29:40 am
Any website is subject to loads of attack daily. This being said, we have human rights NGOs (eg amnesty) that are likely to be more specifically targeted, and the usual big visible like Mozilla or Wikipedia for instance that use CiviCRM.

Oh, one last thing, the weakest link is likely to be the users, and if I want to go into your website, I'll try guessing the password of the less IT navvy people on your team, and try as the password his first name, last name, "password", the name of this wife or kids ... and that's likely I'll be in quickly.

X+
-Hackathon and data journalism about the European parliament 24-26 jan. Watch out the result

Pages: [1]
  • CiviCRM Community Forums (archive) »
  • Old sections (read-only, deprecated) »
  • Support »
  • Pre-installation Questions (Moderator: Dave Greenberg) »
  • Security - CiviCRM if you might get hacked?

This forum was archived on 2017-11-26.