Evan Schuman's StorefrontBacktalk
Techniques, Tools, and Tirades about Retail Technology and E-Commerce
Search
About Us
Advertise
Newsletter
Contact Us
Click To View All Categories
CRM
E-Commerce
In-Store
IT Strategy/Industry
Mobile/Wireless/Contactless
Payment Systems
RFID
Security/Fraud
Social Networks
Software
Supply Chain
advertisement
Top Stories
Mobile Cannibalism: Get Used To It
Could Chat Transcripts Be Security Minefields?
How Far Should Check-In Mobile Apps Go?
Google's Latest Social Search Falls
Far
Short Of What Retailers Need
Mobile Web Performance Erratic At Best: Nordstrom, QVC Good; Levi, REI Bad
Franchise IT: The Movie
North Carolina's E-Tail Amnesty Program Rejected By 94 Percent
Visa Raises The Bar For PA-DSS Applications And Vendors
In New York, One-Third Of Grocery Price Scanners Fail
Staples, Office Depot, OfficeMax Are Sued For Their Web Sites—And Much Of The Rest of E-Tail Could Be Next
Bad Week For Global Security
Still More Of The Dumbest Wireless Security Errors
FROM RISNews: Bankruptcy Watch: Eight Retailers in the Red
advertisement
Newsletter Signup
Newsletter
Quickly catch-up on the latest in E-Commerce and Retail Tech with our free weekly newsletter, with urgent bulletins as news merits.
Sign Up
advertisement
Read StorefrontBacktalk's Retail Realities Column every week at CBSNews.com. Please click here for an archive of those columns.
Most Recent Comments
The mobile challenge is less about supporting the devices and more about having the skill and tenacity to integrate the ordering app into the multitude of POS networks/software iterations.
-Dan Stiel
Mobile Web Performance Erratic At Best: Nordstrom, QVC Good; Levi, REI Bad
Richard Nedwich
Good article, thanks. One possibility that comes to mind to level the playing field, or make the shopping experience 'handset agnostic,' is that most smartphones are coming equipped with WiFi. Retailers *can* control that experience by offering highly available, reliable and good performing WiFi connectivity to their in-store shoppers.
Read more...
North Carolina's E-Tail Amnesty Program Rejected By 94 Percent
xcergy
That 94% know that what NC is doing is ILLEGAL, along with the concept of taxing advertisers who use commission ads on their websites and blogs (Amazon Tax). The problem of collecting Use Tax is a consumer issue, not one for online retail. States should work on enforcing existing Sales Tax Law, not making new bad law designed to put small business out of business.
Read more...
Mobile Cannibalism: Get Used To It
Dan Stiel
The challenge is less about supporting the devices (iPhone, iPad, Android, Blackberry, et al). That's actually easier than you might first think. The bigger issue for operators (not our client, I might add) not mentioned in your article, is having the skill and tenacity to integrate the ordering app into the multitude of POS networks/software iterations, and vintage systems a multi-unit operator tends to support.
Read more...
Vikas Goyal
True. Its more about customer retention than acquisition.
Read more...
Kill All The Passwords
Jay Libove, CISSP, CIPP
This article does mention, but does not give enough attention to, the fact that the attacks discussed are only feasible when the encrypted password file can be copied and subjected to an offline attack. The trick is to have authentication performed on a separate, much more strongly secured host - such as an Active Directory Domain Controller, or a Kerberos server, or a NIS+ server, or even using something as banal as an LDAP-over-SSL authentication dialog. In these environments, the odds of the "password file" being stolen and subjected to an offline attack go to near zero, and only online attacks may be carried out by the attacker. With sensible exponential backoff between failed password attempts, lockout after a modest number of failed attempts on a single account, and pattern detection, that minimum 7 character password is quite secure enough. Passwords aren't dead yet for security purposes, and they will be with us for a very long while to come for practical purposes. The trick is to employ them correctly.
Read more...
Joe G.
The possibilities you describe are years away from being implemented at best, so for the moment passwords are an ugly reality. Luckily, password managers can easily manage hundreds of passwords of any length. The only thing a user needs to remember is the master password. It seems like an easier task to educate users on how to use password managers rather than implement complex security technology on a global basis.
Read more...
New Gift Card Rules Will Make That Plastic Even More Of A Hot Potato
Ray
Few of the published reports mention the ECO-Gift CARD Act and a lot of merchants are confused about the deadlines and the eligibility requirements. The good news is that the ECO-Gift CARD Act is only 2 pages long and fairly easy to understand for us regular, non-lawyer types. Anyone can download it by doing a search for HR5502 at the Congress.gov web site.
Read more...
The Danger Of Assuming Perfection
C. F.
I do not see why people take it so personally. I tend to agree with Walt in that the keys should be able to be decrypted relatively easy. Yes sure certain constants have to be met first (such as having the background to do encryption, having access to the data in the first place and other items). Since all algorithms are based on a mathematical equation it stands to reason like the simple problem (y+100=900) what is Y it would be somewhat similar for cryptography in its standard form.
Read more...
A Reader
But security has to be 100% perfect, all the time. You can't build 98% of a castle wall and expect to keep out 98% of the barbarians. Settling for a second-rate cryptographic solution is the same thing, but because you don't understand the problem, you can't see that the walls don't actually encircle the entire castle.
Read more...
Stop Making Friends And Start Making Money
Pete Reilly
If I'm a brand, why do I want to advertise Foursquare's brand? Why do I want them to collect data on my locations and customers simply to have them sell it to my competition? Why do I want to direct my users to an application like Foursquare that is going to attempt to lure me to the location down the street with a better deal? Mobile and location based services represent an amazing opportunity to engage and influence the consumer like never before. I believe once brands understand the data they are giving up and the ability to leverage their customers 'fan base', they will start to add this functionality to their own mobile presence in addition to leveraging these service.
Read more...
Fabien Tiburce
The privacy implications of that application run deep. Being impersonated and burglarized because of one's careless social media exposure doesn't just happen to other people. Companies beware: just because an app/platform lets (or encourages you to) share personal data, doesn't mean you should put your users through this.
Read more...
Too Much Encrypt = Cyberthief Gift
Bill Bittner
Encryption should be left to the experts. This does not mean retail managers should not have a high level understanding, but they must rely on certification and vulnerability tests to validate their implementations. It also means there is an opportunity for implementation modules with clear API’s that give casual users the means for implementing secure environments.
Read more...