
Originally Posted by
lankeeyankee
I'm not sure what the developers of Apsona are getting out of this?? They don't charge for the service and the scripts are hosted on their server, so this is costing them money in development time/customer service (in this forum and elsewhere) and server costs. You have to create an account to even use this service, what's that about?? There is nowhere to make a donation to the project as far as I can see, so again what does Apsona have to gain from this?? You'll notice on their site there is no mission statement, no about us, no telling you the reason why they are doing what they are doing.....
Am I just being paranoid? Why isn't this released as a product that is entirely hosted on the client server?? Why do I have to use remote scripts to use this product? Why do I have to create an account? I just can't get my head around doing all of this for free.... am I missing something? There isn't even a section on their site to hire them for commercial applications/modifications/etc, so how are they making any money from this? It can't be all out of love....
It looks kind of cool and I'd like to try it out but I have serious misgivings since the scripts doing the real work are on a remote server so I have no way to DEFINITIVELY know that all scripts are 100% benign since I can't look at the code that is interfacing with my cart's admin section!! We are pretty large and have a lot of sensitive data that could possibly be "harvested" for other uses.
I keep coming back to these questions every time I see this thread. And this statement from the Apsona's site FAQ:
"The ShopAdmin system works entirely within the context of your shopping cart application. It does not cause any security risks." is pretty vague and doesn't inspire confidence since it gives no specific details about how it interacts with your cart, and of course, since the scripts are hosted remotely there is NO WAY TO VERIFY THIS!! Plus, it DOESN'T work "entirely within the context of your shopping cart application" since it's using scripts that are remotely hosted, sorry to sound like a broken record and all that....but
Why not release this to be hosted on the individual's server with open source - non-obfuscated- code?? What do you, Apsona, have to gain by hosting this on your servers and forcing people to create an account before they can use it?? What am I missing here? Am I alone in thinking these things?? Does anyone agree with this? Or am I just being paranoid about letting an unvetted script full access to my data?
Bookmarks