Logo Logo
  • Platform
    • Products
      • Why Core dna
        See how Core dna transforms your digital business.
      • eCommerce
        Power your eCommerce ambition
      • CMS
        For marketers with vision, not code
      • Automations
        Automate your way to success
      • DXP
        Build, manage, and scale your digital properties in one place.
      By Role
      • Developers
        Modernize your web presence without ripping or replacing anything.
      • Executives
        Empower marketers, free up IT team and slash costs at the same time.
      • Marketers
        Total control, without the development team.
      Company
      • Customers
        Helping power the digital presence of hundreds of customers
      • Features
        Content and commerce features.
      • Services
        From digital transformation strategy to scaling your digital business.
      • Admin login
        Access to Core dna DXP 1 admin
  • Solutions
    • Use Cases
      • B2B
        Go directly to customers with an all-in-one B2B platform.
      • B2C
        Connect to shoppers anytime, anywhere with our B2C eCommerce solution
      • Marketplace
        Multi-vendor eCommerce marketplace platform.
      • Content
        Craft content with ease, then deliver it anywhere.
      • Headless
        A hybrid headless platform loved by marketers and developers.
      • Infrastructure
        Advanced cloud infrastructure built for scale and security.
      By Industry
      • Direct to Consumers / Manufacturing
        Get the tools and experience to thrive in the new direct-to-consumer world.
      • Education
        Create a powerful online presence with your school website.
      • Franchises
        Seamlessly push brand-approved marketing to all locations or specific locations - easily.
      • Retail
        Sell with excellence in-store and online.
      • Media
        Don’t just break news, break news everywhere.
      • Travel & Tourism
        Give travellers the speed and reliability they demand.
      • Membership Organizations
        Empower Your Membership Management with Smart Technology
  • Resources
    • Insights
      • Blog
      • Guides
      • FAQ
      Developers
      • Getting started
      • Documentation
      • API
  • Pricing
  • Partners
    • Why Partner?
    • Program Overview
    • Become a partner
Get started
 
  1. Home
  2. Core dna insights

Panama Papers: 2 Key Breaching Open Source Platforms

Panama Papers: 2 Key Breaching Open Source Platforms
Sam Saltis
April 12, 2021 - (6 min read)

Platform Strategies | Website performance | Replatform
In a hurry? Get how to choose a CMS

Introduction

The hacking of Mossack Fonseca’s client portal leaked over 11.5 million documents, 4.8 million emails and 2.6TB of data - the largest leak in history. Prime ministers have resigned, business people are being scrutinized and over 30 countries have launched investigations against individuals and companies.

The information was assumed to have come from unencrypted emails through an outdated (2009) version of Microsoft’s Outlook for Web portal.  

There is, however, a well-founded belief that the hackers found their way into the law firm's system through unpatched and outdated versions of the WordPress and Drupal CMS.

“Mossack Fonseca's client portal is also vulnerable to the DROWN attack, a security exploit that targets servers supporting the obsolete and insecure SSL v2 protocol. The portal, which runs on the Drupal open source CMS, was last updated in August 2013, according to the site's changelog. Exposing the website to the Drupalgeddon vulnerability, also known as SA-CORE-2014-005 affected millions of websites back in 2014.”

Full details can be found at Wikipedia Panama Papers including what each of the countries is doing.

This incident again highlights some of the gaps in the argument that “the technology doesn’t matter”.


On this page:

    The Open Source Debate

    For many years, there have been ongoing debates between open source proponents and commercial software companies. The debate has been passionate, each side has devout beliefs.

    The open source argument centers on ownership of source code and benefiting from a community of contributors. In ‘selling’ the benefits of open source, providers refer to the portability of the source code if things don’t work out? The real world reality is that web developers each have their own trusted tools and methods, their own idiosyncrasies and changing providers is really the start of the redevelopment process.

    You left that other provider for a reason right? So when your new provider tells you that the quality of the code is poor, that there is a better library or framework and that updates need to be performed then it validates your beliefs.

    What has eventuated however is very different;

    With the ownership of the source code comes with tremendous responsibility to maintain it.

    The argument relating to freedom of ownership is a misguided perception which we would say is purported by those who profit from providing the extensive range of services required to maintain an open source solution.

    The problem is formed when the site is launched and with each patch or version update of the open source platform, the issue grows silently in the background.

    The owner of the website is focused on growing their business, they are not equipped to properly maintain their platforms - most companies don’t have the first clue of what it requires to protect software and databases from malicious online attacks.

    The folks at Mossack Fonseca probably never gave the technology a second thought once the site was deployed. Most likely the provider who built the site used a library of plugins, each of which requires its own maintenance.

    Meanwhile, Mossack Fonseca are tracking along thinking “If it broke, we'll call the developers to fix it”.

    There are a burgeoning array of providers like Acquia and Automattic, along with hosting companies like Hostway, Pantheon, and Omega8 that have seen the problem and are providing potential solutions to some of these maintenance issues.

    But how they can protect sites from poor coding and outdated components?

    Clearly, the leadership of Mossack Fonseca is at fault for not managing the risks associated with the maintenance of their CMS platform.

    But should this maintenance be something that needs leadership focus? What are the options for companies who can’t afford a full development and networking team?

    Bonus material: The ultimate guide to choosing a CMS (plus 100+ questions you should ask your CMS vendor)

    [Option 1] Outsource to a hosting provider who has a managed services

    Companies who will support the full stack including the software. These teams will perform ongoing weekly maintenance and security testing to find holes & components that have failed.

    Read this next: Why Your eCommerce Website Needs Stronger Security Measures

    [Option 2] Implement a SaaS solution

    Coredna, for example, takes care of the full stack, and for a fixed fee each month will deliver a scalable, managed platform that continuously evolves with new features and updates.

    [Option 3] Engage a commercial software provider

    And make the maintenance and network security part of the ongoing contract.

    No longer can we look at the internet as something that happens "over there". After more than 20 years, the Internet has become far more complicated, intertwined and embedded in our lives. 

    Here are some other past articles we’ve written related to these topics:

    • Comparing Open & Closed Source Software
    • 8 Reasons To Move To SaaS For Your Next Website Project
    • How to Choose The Right CMS Platform to Help Drive Your Business Growth
    • How to Choose a SaaS CMS: The 9-Point Checklist
    • Drupal as a CMS and Commerce Platform: The Ultimate Guide
    • Using WordPress as an Enterprise CMS: 9 Things You Should Know
    Have questions? Speak with our experts to find your ideal content solution
    Sam Saltis
    Sam Saltis

    Sam Saltis is the founder and CEO of Core dna, a digital experience platform (DXP) that helps digital teams build and optimize complex, dynamic websites with less code than ever before. Sam has more than 30 years’ experience building technology solutions for various industries and sectors, such as government, business and tourism. 

    He leads a team of technology experts who share his vision of empowering clients to harness the Internet to scale their businesses and enhance their relationships.

    Previous PostContentstack CMS: Is It Really the Best Headless Option?
    Back
    Next Post4 eCommerce Website Elements You Should Personalize ASAP

    Related guides

    • What B2B Commerce Features to Look For in a Platform
    • Payment Gateways Compared: Which One Boosts Your Sales?
    • Is SEO Dead? How to Update your Seo Strategy to 2025
    • How Hyper-personalization is Impacting Digital Experiences
    • Headless Commerce or Traditional? The Hidden Trade-Offs
    • What is DICE Framework and How to Implement it
    • Webhook vs API? Choose The Right Tool for Your Integrations
    See all guides

    Related posts

    What B2B Commerce Features to Look For in a Platform

    Platform Strategies

    What B2B Commerce Features to Look For in a Platform
    April 12, 2025 ( 13 min read )
    Payment Gateways Compared: Which One Boosts Your Sales?

    eCommerce Business

    Payment Gateways Compared: Which One Boosts Your Sales?
    March 22, 2025 ( 5 min read )
    Is SEO Dead? How to Update your Seo Strategy to 2025

    Content Marketing

    Is SEO Dead? How to Update your Seo Strategy to 2025
    March 21, 2025 ( 9 min read )
    How Hyper-personalization is Impacting Digital Experiences

    eCommerce Business

    How Hyper-personalization is Impacting Digital Experiences
    March 18, 2025 ( 9 min read )
    Headless Commerce or Traditional? The Hidden Trade-Offs

    Platform Strategies

    Headless Commerce or Traditional? The Hidden Trade-Offs
    March 11, 2025 ( 13 min read )
    What is DICE Framework and How to Implement it

    Platform Strategies

    What is DICE Framework and How to Implement it
    February 25, 2025 ( 5 min read )
    Webhook vs API? Choose The Right Tool for Your Integrations

    eCommerce Business

    Webhook vs API? Choose The Right Tool for Your Integrations
    February 19, 2025 ( 4 min read )
    Elevate Your CX with the Best Digital Experience Platforms

    Content Marketing

    Elevate Your CX with the Best Digital Experience Platforms
    February 08, 2025 ( 6 min read )
    How Digital Employee Experience Transforms Workplace Culture

    Content Management

    How Digital Employee Experience Transforms Workplace Culture
    January 17, 2025 ( 7 min read )
    The Truth About SAP Commerce Cloud: Pros, Cons & More

    Web Development

    The Truth About SAP Commerce Cloud: Pros, Cons & More
    January 10, 2025 ( 9 min read )
    Website Replatforming: Smart Move or Hidden Risk?

    Web Development

    Website Replatforming: Smart Move or Hidden Risk?
    January 02, 2025 ( 22 min read )
    No code, big wins! How to built an LMS in weeks

    About Core dna

    No code, big wins! How to built an LMS in weeks
    December 22, 2024 ( 6 min read )
    Solutions by Role
    • Partners
    • Developers
    • Executives
    • Marketers
    Solutions by Need
    • Intranet
    • Event Management
    • Content Management
    • B2b eCommerce
    • B2c eCommerce
    • Headless
    • Marketing
    Solutions by Industry
    • Community
    • Healthcare
    • Finance
    • Technology
    • Hospitality
    • Franchise
    • Education
    • Travel & Tourism
    Company
    • About Us
    • Why Core dna
    • Partner Ecosystem
    • Customers
    • Careers
    • Contact Us
    • G2Crowd Reviews
    Resources
    • Blog
    • Guides
    • Admin login
    • RSS Feed
    • Documentation
    Support
    • Help
    • Videos
    • Network Status
    • GDPR
    • Privacy Policy
    • Terms & Conditions
    • Fair Use Policy
    Get our latest articles
    Success! You've been added to our email list.
    Melbourne

    348 High Street

    Prahran, VIC 3181

    Australia

    +61 3 85639100

    Boston

    55 Court St, Level 2

    Boston, MA 02108

    USA

    +1 617 274 6660

    Berlin

    Belziger Str. 71

    Berlin 10823

    Germany

    +1 617 274 6660

    Go wow them! ™ | Core dna copyright ©  2025.