Charities are more likely to have poor website security than organisations in other sectors, according to the Web Application Annual Security Report 2009 which was published this week. What kind of insecurities did the report find?
Not having account lockout mechanisms in place, which stop hackers from repeatedly guessing passwords. That’s why on my websites (which use the WordPress CMS) I now use a plugin called Login Lockdown which locks people out of the login form if they keep entering incorrect passwords.
Charities often choose insecure passwords, which increases the chances of unauthorised access to accounts. Too many charities use their organisation’s own name or location as their password, sometimes with a letter replaced by a number. Anything that can be guessed is really poor security. LASA’s Knowledgebase has advice on choosing secure passwords. >> Read more…











