During one of the recent Application Security training courses I delivered recently, one interesting example I gave during a section on "Our dependencies on Technologies and Frameworks that we don't fully understand" was the concept of how much of a threat to the UK economy is Google?
For example if Twitter or Facebook were not available from the UK, I don't think the impact would be significant.
But if Google and all its services (search, mail, calendar, maps, geolocation, docs, spreadsheets, contacts, Google ID) was suddenly not available, I bet that there would be a significant disruption to a LOT of individuals, business and government agencies.
There is a lot of talk in the UK about the Geopolitical threat of Russia (and its control on natural resources used by the UK), but I'm pretty sure Google can do more damage.
Of course that it would be economical/business suicidal for Google to do such a thing, but that doesn't make it less real or dangerous.
A personal blog about: transforming Web Application Security into an 'Application Visibility' engine, the OWASP O2 Platform, Application/Data interoperability and a lot more
Showing posts with label Google. Show all posts
Showing posts with label Google. Show all posts
Saturday, 6 February 2016
Friday, 30 May 2014
Game to learn how to find XSS Bugs (by Google)
As you can see on https://xss-game.appspot.com and read on Google Launches Game to Teach XSS Bug Discovery Skills , this could be a really interesting way to reach developers.I will try to give it a test drive and see how easy/hard it is.
I wonder if this could also be used to teach kids about application security (and how fun it can be to break it :) )
Labels:
Google,
Learn-to-Code,
Security
Thursday, 8 May 2014
Watching google crawl TeamMentor site (10m after blog post)
This is really interesting and telling of Google's crawling speed and updates.
I posted What are the main TeamMentor use cases? (and "Don't copy and paste from Google, copy and paste from TeamMentor") 10 minutes ago, and while looking at the new 'TM 3.4.1 real-time TeamMentor Activity' viewer, I noticed a number of 404s:
I posted What are the main TeamMentor use cases? (and "Don't copy and paste from Google, copy and paste from TeamMentor") 10 minutes ago, and while looking at the new 'TM 3.4.1 real-time TeamMentor Activity' viewer, I noticed a number of 404s:
Labels:
Google,
TeamMentor
Sunday, 15 December 2013
Blogger search is still broken and workaround to create a simpler (but working) blog search
I was trying to ignore this and see if Google Blogger team would fix it, but after a couple weeks (or more) it is still broken, and is starting to affect me (because I blog so that Future Self is able to find those ideas (like my Today Self, which is not able to find for what It think it is there).
Labels:
Future Self,
Google
Tuesday, 13 August 2013
The speed of Google's crawling updates is impressive (with Bing and Yahoo not even on the map)
When I was researching the Adding Custom Descriptions and Content to Fortify using the RulePack's CustomDescriptionRule element post, there was not one direct hit/result for CustomDescriptionRule in any of the major search engines (it really makes you fell alone in the world, when there is no info out there about the current research topic :) ).
So what does it look now, after just 30m of posting it (I actually bet that Google got there sooner, but I don't have the screenshot to prove it).
Here are google's results:
So what does it look now, after just 30m of posting it (I actually bet that Google got there sooner, but I don't have the screenshot to prove it).
Here are google's results:
Labels:
Google
Thursday, 23 May 2013
Trying Google Groups as the OWASP O2 Platform mailing list
This is something that some OWASP project leaders have talked/tested in the past, so to try it I moved the current mailman-based O2 list to the new Google Groups (which look much better than a couple years ago)
Friday, 17 May 2013
The post that broke Feedburner
Here is something weird, I was noticing that some of my recent posts were not having the normal traffic and after digging a little bit I found that the last post on the xml feed:
Labels:
Google
Wednesday, 23 January 2013
Why does YouTube still require Flash in Jan 2013!!!!
I thought flash was over and I find it ridiculous that I need to have it just to see a Video:
Monday, 8 October 2012
Idea: Sync Blogger Posts with a GitHub repository
From the end of the So if my blog account is compromised can I sue Google? post comes an interesting WebService idea:
Sync Blogger posts with a GitHub repository
Sync Blogger posts with a GitHub repository
Labels:
Git,
Google,
Half-baked Idea
So if my blog account is compromised can I sue Google?
After another occasion where I connect to this blog via HTTP (in a Starbucks) I'm left wondering how long will it be until my account is compromised? And what could I do when that happens?
As you can see in Blogger in HTTP only? What happened to HTTPS? this is not news for me.
Although there seems to be an recent improvement (i.e. HTTPS actually works if directly used), the question is why doesn't Google do it?
Why doesn't Google provides an 100% SSL experience?
I'm speculating, but it has to be a mix of:
As you can see in Blogger in HTTP only? What happened to HTTPS? this is not news for me.
Although there seems to be an recent improvement (i.e. HTTPS actually works if directly used), the question is why doesn't Google do it?
Why doesn't Google provides an 100% SSL experience?
I'm speculating, but it has to be a mix of:
- Not enough compromises/attacks (if an attack happened but there is no public record of it, did it really happened?)
- Not enough public and high-profile compromises/attacks (more realistic)
- The Hardware costs of making that change (which is weird, since I would assume that Google is able to provide iSSL in at a cost-effective way)
- The Software/Application costs of making that change (this sounds more realistic since some apps are hard to move to SSL due to its dependencies and side effects)
- Not being sued on this topic (because if they were, the maths/business-case/ROI would be simple)
The last point is an interesting one, since:
- There is clearly a case that Google is not taking due care with their customer's data
- Google has publicly stated the importance of HTTPs (see HTTPS security for web applications )
- In 2012 there is no 'real' or 'defensible' technical excuse for not using SSL all the time
I guess with the teams of clever lawyers and developers at Google, their conclusion was that (as Oct 2012) there is a 'real' or 'defensible' business excuse for them to act this way.
Another fine example of why Security is so hard to do from a business point of view.
Here it is a nice service, used by millions of customers with no (reported/public) problems, and then, here come the Security TAX forcing code and infrastructure changes!!! (with no visible customer benefit)
Tip: Just in case, I just used a great little feature from the Blogger admin panel which is the 'Export Blog' (this gives you an xml file with your entire blog contents. Now if only I could get Blogger to sync it with a GitHub repository
Friday, 27 April 2012
Blogger in HTTP only? What happened to HTTPS?
UPDATE (2016): Blogger has limited support for https, see https://security.googleblog.com/2016/05/bringing-https-to-all-blogspot-domain.html
Now that I'm blogging more, I'm finding the need to blog from insecure locations (like a coffee shop or conference).
But unfortunately it doesn't seem to be possible to use SSL with Blogger? WTF! in 2012?
After this 2009 letter Google moved some of its web apps to SSL (see Google's answer at HTTPS security for web applications) but blogger seems to have been missed!
At the moment it doesn't seem to be a way to write a blog post (like this one) without risking my sessionID being compromised. Am I missing something obvious?
Here is are thread Can I use an HTTPS connection for editing and posting on Blogger? (which points to a non-existing thread) that implies that Google doesn't do this due to performance issues.
Also annoying is the fact that https://diniscruz.blogspot.co.uk/ doesn't work! So how can I know that this blog's content is read as it was written (ie. without its content being tampered with)
On the topic of OWASP, note how there is no mention to it on the letter. Yes this letter is from 2009 but if it was written today, would OWASP be there? (this is what I'm now calling OWASP MIA (Missing In Action))
On that topic, why don't we write another letter to Google asking for them to extend their security efforts into blogger!
Also, if Google doesn't care about this and give us no solution, what other options do we have? What about a 'cloud' service that gives me secure access to this blog?
Now that I'm blogging more, I'm finding the need to blog from insecure locations (like a coffee shop or conference).
But unfortunately it doesn't seem to be possible to use SSL with Blogger? WTF! in 2012?
After this 2009 letter Google moved some of its web apps to SSL (see Google's answer at HTTPS security for web applications) but blogger seems to have been missed!
At the moment it doesn't seem to be a way to write a blog post (like this one) without risking my sessionID being compromised. Am I missing something obvious?
Here is are thread Can I use an HTTPS connection for editing and posting on Blogger? (which points to a non-existing thread) that implies that Google doesn't do this due to performance issues.
Also annoying is the fact that https://diniscruz.blogspot.co.uk/ doesn't work! So how can I know that this blog's content is read as it was written (ie. without its content being tampered with)
On the topic of OWASP, note how there is no mention to it on the letter. Yes this letter is from 2009 but if it was written today, would OWASP be there? (this is what I'm now calling OWASP MIA (Missing In Action))
On that topic, why don't we write another letter to Google asking for them to extend their security efforts into blogger!
Also, if Google doesn't care about this and give us no solution, what other options do we have? What about a 'cloud' service that gives me secure access to this blog?
Sunday, 22 April 2012
Security evolution into Engineering Productivity
I just started reading the 'How Google Tests Software' book and Patrick Coperland Forward really hit me.
He basically describes how Testing inside Google went from being a separate discipline (Testing vs Coding) to a integral part of the development process and eventually evolved into what is now called 'Engineering Productivity'
And that is exactly what application security needs to do. We need to stop being a TAX and start delivering Engineering Productivity (which ironically is already happening today, since, when you find a good success stories on Application Security, you usually find a good Engineering Productivity story).
You can read it Patrick's Forward online at Safari and just replace Testing with Security.
Just like security is today, testing (at Google) was a separate discipline. With separate skill sets, objectives and focus.
A couple key issue were:
Today we have the exact same issues in security. Most Security teams don't have strong development backgrounds and even when they do they have very little experience in actually writing real world applications (vs mini-tools and scripts).
Also today, a very large number of successful security teams are happy with being a 'badometer' and delivering PDF after PDF to their clients (vs delivering Tests and Automation of their knowledge/findings)
In a way that is why the O2 Platform doesn't have more traction. There are not enough players that have the type of problem that the O2 Platform was designed to solve (for example look at the latests http://googletesting.blogspot.co.uk entries and that is exactly the type of stuff that I do with O2 (I guess to get the Googlers interested I also need to make O2 run in Javascript and Python :) )
More and more I think that Application Security needs to align itself with Testing, since (as the 'How Google Tests Software' book shows) they are much more mature in figuring out how bake their practice into the development lifecycle.
What is interesting is that Application Security does have it very special place in this ecosystem, since usually everybody else cares that 'THE Application Works' , while the security camp is probably the only one that cares about 'HOW the Application works'
So the challenge is how do transform our current Security Practices into an Engineering Productivity world
Related Posts:
He basically describes how Testing inside Google went from being a separate discipline (Testing vs Coding) to a integral part of the development process and eventually evolved into what is now called 'Engineering Productivity'
And that is exactly what application security needs to do. We need to stop being a TAX and start delivering Engineering Productivity (which ironically is already happening today, since, when you find a good success stories on Application Security, you usually find a good Engineering Productivity story).
You can read it Patrick's Forward online at Safari and just replace Testing with Security.
Just like security is today, testing (at Google) was a separate discipline. With separate skill sets, objectives and focus.
A couple key issue were:
- the lack of development skills that Testers had,
- how good developers (in the testing team) would be absorbed by development teams
- how the existing testers were ok with the status quo
- how non-integrated the whole process was
Today we have the exact same issues in security. Most Security teams don't have strong development backgrounds and even when they do they have very little experience in actually writing real world applications (vs mini-tools and scripts).
Also today, a very large number of successful security teams are happy with being a 'badometer' and delivering PDF after PDF to their clients (vs delivering Tests and Automation of their knowledge/findings)
In a way that is why the O2 Platform doesn't have more traction. There are not enough players that have the type of problem that the O2 Platform was designed to solve (for example look at the latests http://googletesting.blogspot.co.uk entries and that is exactly the type of stuff that I do with O2 (I guess to get the Googlers interested I also need to make O2 run in Javascript and Python :) )
More and more I think that Application Security needs to align itself with Testing, since (as the 'How Google Tests Software' book shows) they are much more mature in figuring out how bake their practice into the development lifecycle.
What is interesting is that Application Security does have it very special place in this ecosystem, since usually everybody else cares that 'THE Application Works' , while the security camp is probably the only one that cares about 'HOW the Application works'
So the challenge is how do transform our current Security Practices into an Engineering Productivity world
Related Posts:
Labels:
Google,
Philosophy,
Security as TAX
GTAC 2011 - Google Test Automation Conference
Just found GTAC (http://www.gtac.biz/home) and it looks like there are a good number of talks that are really interesting.
Here are the Talks page http://www.gtac.biz/talks which ironically page crashes Chrome since it tries to load up a very large number of video players :)
The agenda is quite impressive http://www.gtac.biz/agenda and although there is only one security focused presentation ('How Hackers See Bugs' by Hugh Thompson) I bet security is covered by other presentations.
Look for example how there is no OWASP references (including I believe) project leaders. If OWASP wants to change application security, this is the one of the places to be. That said, not all is lost, since I just noticed that Hugh Thompson did a presentation at OWASP MSP in March (http://hughthompsonowaspmsp.eventbrite.com , videos not online)
Labels:
Google
Subscribe to:
Posts (Atom)