On The Insider: Robert Pattinson's New Leading Lady
BNET Business Network:
BNET
TechRepublic
ZDNet

November 5th, 2007

Michael Barrett on Web 2.0: This stuff scares the hell out of me

Posted by Phil Windley @ 10:42 am

Categories: Security, Web Technology, Wired & Wireless

Tags: Web, WEP, Michael, Channel Management, Web 2.0, Network Security, Wi-Fi, Wireless, Security, Marketing

Michael Barrett at DefragWhen Michael Barrett (CISO, Paypal) heard the Eric Nolin was putting on Defrag, he called up and said “I’d like to come and talk because this stuff scares the hell out of me.” His key messages: (a) we’re doomed to repeat history if we ignore it and (b) security is hard. Not exactly earth shattering news–but one we’re inclined to ignore in our giddy rush to new uses for the Web.

Michael puts up a rogue’s gallery of protocols that have missed security: telnet, SNMP community strings, Kerberos, and WEP. He says of WEP: “What were they thinking?” WEP cost TJ Maxx somewhere in the $200 million dollar range. He adds OpenID to the list. When it’s used outside specific use cases, OpenID is open to phishing attacks.

The Web 1.0 standards are broken: You can’t write a safe Unicode webapp. Most Web sites are vulnerable to cross site scripting. It’s impossible to write software that fully validates it’s inputs and screens it’s outputs. DNS poisoning is a threat on any network–especially open ones. How can you build secure eCommerce when 30% of the endpoint PCs on the Internet are compromised?

What’s worse, nothing in Web 2.0 has done anything to fix the Web 1.0 issues–it’s simply given us more poorly executed protocols and standards to worry about. A couple of examples:

The problem is exacerbated the fact that even well-designed protocols get implemented poorly by programmers who don’t fully understand them.

Of course, there’s no silver bullet. A very reliable source recently told Michael that the take from electronic crime is now higher, worldwide, than that from illegal drugs! The bad guys are extremely well funded and the take is huge. As a result, the problem is likely to get worse–especially if we ignore it.

Phil Windley is an Associate Professor of Computer Science at Brigham Young University. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 11 Talkback(s)
Simplify
If (ALL) programmers would make things more simple instead of more complicated then there would be some hope.

Also, keep in mind that a digital ID is nothing more then a DRM on the user.... (Read the rest)
Posted by: emenau Posted on: 11/08/07 You are currently: a Guest | | Terms of Use
Phishing scares me  pierreir | 11/05/07
Wow...  jasonp@... | 11/05/07
RE: Michael Barrett on Web 2.0: This stuff scares the hell out of me  l1el@... | 11/06/07
Perhaps if...  lonniemcclure | 11/06/07
Journalists should know grammar  verbila | 11/06/07
Here's a usage hint  geedavey@... | 11/07/07
Why do we appear to have  legalista | 11/07/07
Clean up your own backyard  craig.thomler@... | 11/06/07
Customer Service?  dr_who@... | 11/06/07
Lost 1000.00 thru Paypal  Maxscunion@... | 11/06/07
Simplify  emenau | 11/08/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
Save time with automated shipping solutions
The Business Essentials Guide provides you useful tools and templates to help grow your business and save you time with automated shipping solutions.
Visit the UPS Business Essentials Guide
Reduce risk. Reduce complexity. Increase reliability.
A simplified IT environment isn't just less complex. It's also more reliable. Standardize on a single Linux platform with SUSE Linux Enterprise from Novell, and get the world's most interoperable Linux
Learn more >>
Keep Up With The Latest In Document Management with The DocuMentor.
Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
Learn more >>
Reduce risk. Reduce complexity. Increase reliability.
A simplified IT environment isn't just less complex. It's also more reliable. Standardize on a single Linux platform with SUSE Linux Enterprise from Novell, and get the world's most interoperable Linux
Learn more >>
The best support in the Linux business
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.
Learn more >>
Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.
Learn more about the free, six-month trial offer>>
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Meet Doc