Re: WebCup 2015 (was: Website security)

From: Ish Sookun <ish_at_hacklog.in>
Date: Fri, 10 Apr 2015 09:27:54 +0400

Hello Vincent,

On Fri, Apr 10, 2015 at 12:50 AM, vincent pollet <vincent_at_pongosoft.com>
wrote:

>
> I am actually one of the admin for Webcup Mauritius website. You guys are
> right it is a wordpress and the choice of the theme can always be discussed
> but at the end of the day it is not really our choice .... The website is
> managed by the team in la Reunion and other countries like us do not have
> full admin access. Which is normal as the competition is not only in
> Mauritius but in Indian Ocean so it need to be centralized somehow and to
> satisfy everyone.
>

Thanks for informing you're an admin for WebCup MRU website
​ :-)
​However, I don't think that one needs to have full admin access to push
recommendations upward.


>
> Webcup registration will be officially launched on Monday in Port Louis
> and regarding security issues well... you guys should know better than
> other that 100% security does not exist in our sector :)
>

​As per the press communiqué[1], registration starts 30 March 2015.​
I did not mention 100% security but I would expect a minimum that shall
avoid this[2], this[3] and that[4]. Concerned with the rising attack on
"easy deployments" of WordPress even FBI released recommendations[5].


>
> I also want to share with you that the core organization team of the
> Webcup is composed of 4 voluntary workers only to organize an event in
> coordination with Reunion,Mayotte,Comoros Madagascar and Seychelles...
> If you think that something is not rightly done, well we will be happy to
> receive your assistance ! at the end of the day we are not paid for doing
> this and it is the community that is benefiting of it so let me know if you
> guys are ready to help :)
>

If companies are putting logos without any financial help, then I suggest
removing their logos next time. I am not a full-time web developer but I am
a full-time user who can recommend suggestions about some UX/UI.
Server-side I can do tweaking :-)


>
> Lastly regarding web agency installing only a purchased theme and a logo
> you can imagine that when a client is asking for a 10 000 MUR website he
> gets what he pays for. Quality cost money obviously and many agencies are
> lowering down the prices on the local market because clients are simply not
> ready to pay. It will change one day maybe but you have now the situation
> where good agencies prefer to sell abroad than to work for peanuts on the
> local market... that is sad but mentally are evolving and I think it will
> be better in a near future
>
>
If I tell a customer for Rs 10K I am going to :

i) Give you a .com for 1 year
ii) Host your website for 1 year
​iii) Configure your webserver
iv) Apply regular patches on your webserver for 1 year
v) Install WordPress and maintain it for 1 year
vi) Design WordPress theme
... then I am wrong.

I need to make it clear to a customer that my expertise lies server-side. I
do not design webpages. I'll charge only for what I can do but not try
doing other stuffs that is not really in my field and latter tell a
customer, well you got what you paid for. A customer asks for a good
product at a low price without understanding anything about the product.
The proper education needs to be done by the WebDev :-)

Now, still if I want to satisfy 100K customers with full-fledged security
in WordPress at just Rs 10K each, it can happen. Oops! I just can't write
it here otherwise I'll again be caught doing free consultancy.

​[1]
http://maurice.webcup.fr/espace-presse/communique-de-presse-lancement-de-la-3eme-webcup-de-loceanindien-les-23-et-24-mai-2015

[2] http://hacklog.in/hacked-dont-call-cert-mu/
[3] http://hacklog.in/are-mauritian-websites-secure
[4] http://hacklog.in/chili-mu-compromised
[5] http://www.ic3.gov/media/2015/150407-1.aspx

Cheers,

-- 
​Ish Sookun
- Geek by birth, Linux by choice.
- I blog at HACKLOG.in.
https://twitter.com/IshSookun ^^ Do you tweet?
Received on Fri Apr 10 2015 - 05:28:11 PST

This archive was generated by hypermail 2.3.0 : Fri Apr 10 2015 - 05:36:02 PST