Risico's Web 2.0

37
Risico’s Web 2.0 INTEGRATION as the problem to the answer… © hans pronk 2008 (aka [email protected])

description

Een korte overview van de risico aspecten van de brave new web 2.0 world.

Transcript of Risico's Web 2.0

Page 1: Risico's Web 2.0

Risico’s Web 2.0

INTEGRATION as the problem to the answer…

© hans pronk 2008 (aka [email protected])

Page 2: Risico's Web 2.0

2

pre-WEB 2.0 security & integration

Page 3: Risico's Web 2.0

masters of integration orthe ultimate mash-up

Page 4: Risico's Web 2.0
Page 5: Risico's Web 2.0
Page 6: Risico's Web 2.0

trends in the new 2.0 era

deportalizationend of the walled garden SaaS

mash-upswidgets

user-centric identity

the rise of the platform

writable webAJAX

browser as THE ui: everywhere available

user-centric

social networks

syndicationPaaS

Page 7: Risico's Web 2.0

integration & security

controlcomplexitydata spillsnew new new

Page 8: Risico's Web 2.0

right or wrong?

..

the

visi

onai

r?

Page 9: Risico's Web 2.0
Page 10: Risico's Web 2.0

the newapplicationslandscape

Page 11: Risico's Web 2.0

complexity

platforms: the new paradigm:Google | Amazon | Microsoft Live Core | Carolina | Salesforce | 37Signals | (insert favourite platform here)

complexity hidingeconomics of scalespecialization

Page 12: Risico's Web 2.0
Page 13: Risico's Web 2.0
Page 14: Risico's Web 2.0
Page 15: Risico's Web 2.0
Page 16: Risico's Web 2.0
Page 17: Risico's Web 2.0
Page 18: Risico's Web 2.0
Page 19: Risico's Web 2.0

control & faith sharing

the ford firestone case

dealing with service levels / disaster recovery

dealing with popularity“The Remora Business Model”

syndication / rss / “dapper”

old school firewalls issues

Page 20: Risico's Web 2.0

“software is hard”

Donald E. Knuth

complexity

Page 21: Risico's Web 2.0

complexity

API designarchitecturescalinginside versus outside

SOAP versus REST

“put it to REST”?

transport versus message security

Page 22: Risico's Web 2.0

complexity

(accidental)integration on the desktopXSS/XSRF exploit of trust (user|web-

site)JSON

(missing) toolsIDS for app servers

Page 23: Risico's Web 2.0

http://www-1.ibm.com/support/docview.wss?uid=swg21233077&loc=%22%3Cbody%20onload=alert('OWNED')%3E%22

“<body onload=alert('OWNED‘)>”

example xss/xsrf

<img src = "http://bank.example/withdraw?account=bob&amp;amount=1000000&amp;for=mallory">

Page 24: Risico's Web 2.0

data spillsidentity management / privacy

Identity 2.0 aka “user centric identity management” (dick hard)

casual versus strict privacy

the case for OAuth!

open social?

data hygiene example: RSS-feeds

Page 25: Risico's Web 2.0
Page 26: Risico's Web 2.0
Page 27: Risico's Web 2.0

sharing with the world

(private) intelprofiling (ip-address?)

[Plaxo | LinkedIn | Hyves | Facebook | Qik | Trackr]

addressescontactspictures

whereabouts…

Page 28: Risico's Web 2.0
Page 29: Risico's Web 2.0
Page 30: Risico's Web 2.0
Page 31: Risico's Web 2.0
Page 32: Risico's Web 2.0

new… newer… newest

AJAXRuby (on Rails) / RJS / python / …lighttpd / mongrelllibraries, more libraries, and even more libraries

Page 33: Risico's Web 2.0

web treaths

Web 2.0 is a success, as the activities of the real world move online; the criminals follow the money, and the money is now online

credit card companies are still eating the losses; but some areas are making customers more liable for losses

Page 34: Risico's Web 2.0

web treaths

from highly visible media events to financially motivated threats

the true financial attacks don't want to lose connectivity, so infrastructure DDoS attacks are counterindicated

not just windows, now hitting Linux and Mac as well, aiming to compromise Linux servers

Page 35: Risico's Web 2.0

web treaths

large rise in misconfigured, rogue DNSresolvers; estimated 300,000 compromised DNS servers

Google finding 180,000 web servers serving malicious code in their crawls

Page 36: Risico's Web 2.0

“old” security mechanisms not enough / counterproductive

reduce complexity / decoupling

old principles are still truebe aware and…be what you are

wrapping-up…

Page 37: Risico's Web 2.0

www.twitter.com/hnzz

hnzz.jaiku.com

www.hnzz.nl

[email protected]

2008, © [email protected],