Definitely a missed opportunity here :)
What types of App should exist?
At least we should have a couple that expose OWASP materials (books, wiki pages) , projects and events.
I will be a happy guy when this page doesn't look like this:
A personal blog about: transforming Web Application Security into an 'Application Visibility' engine, the OWASP O2 Platform, Application/Data interoperability and a lot more
Showing posts with label OWASP MIA. Show all posts
Showing posts with label OWASP MIA. Show all posts
Wednesday, 27 November 2013
Friday, 14 December 2012
CI is the Key for Application Security SDL integration
The more time I spent with CI (namely with TeamCity) the more my instinct is saying ‘this is how we should be delivering and automating security knowledge!'.
Labels:
Half-baked Idea,
OWASP MIA,
Security,
TeamCity
Sunday, 9 December 2012
Software Labels – Jeff’s OWASP AppSecDC 2010 presentation (another dropped good idea)
An old idea from Jeff Williams (which is spot on) is the need to apply Labels to Software and Web Applications.
The concept is simple, but its implementation is really hard, because of the lack of quality standards/metrics in our industry
The concept is simple, but its implementation is really hard, because of the lack of quality standards/metrics in our industry
Wednesday, 31 October 2012
Etsy.com - A case study on how to do security right?
First a quick disclaimer that as far as I can think of, I don't know anybody at Etsy.com or had any conversations with them in the past.
Following from Nick's presentation on Amazing presentation on integrating security into the SDL , my look into Etsy's Code as Craft blog and my experiment with Graphite (see Measure Anything, Measure Everything, AppSensor and Simple Graphite Hosting).
I have to say that I have been more and more impressed with Etsy's pragmatic and focused approach to application security.
For example check these out:
This is 'real-world' stuff and its what happens when there is a good awareness on the importance and need for doing security.
As you can see, here is a team (from management to engineering) that 'gets' application security, and these are the guys that should be driving a number of OWASP's initiatives, since they represent the 'real-world'. Please correct me if I'm wrong, but a google and owasp search (for 'OWASP Etsy') didn't show a lot of joint activity (the best ones where Nick's participation in the AppSec USA and this job post mentioning the OWASP Top 10). It would be great to see Etsy's guys pushing projects like: AppSensor, ESAPI, Zap, Testing+Developer+Code-Review guides, O2, Exams/Certification, etc...
We (OWASP) need to find ways go get these guys more involved and put them on the driving seat.
In fact, for the next OWASP Summit, we have to make sure these guys are there, working collaboratively with the best minds in Application Security :)
Following from Nick's presentation on Amazing presentation on integrating security into the SDL , my look into Etsy's Code as Craft blog and my experiment with Graphite (see Measure Anything, Measure Everything, AppSensor and Simple Graphite Hosting).
I have to say that I have been more and more impressed with Etsy's pragmatic and focused approach to application security.
For example check these out:
- Scaling User Security (where they described their experience in: 'Rolling out Full Site SSL' and 'Two factor authentication'
- Announcing the Etsy Security Bug Bounty Program
- Couple more posts tagged as 'security': http://codeascraft.etsy.com/category/security/
- Etsy has been one of the best companies I've reported holes to. (reddit thread)
- Effective approaches to web application security (haven't read it but looks like another really 'must see' presentation'
This is 'real-world' stuff and its what happens when there is a good awareness on the importance and need for doing security.
As you can see, here is a team (from management to engineering) that 'gets' application security, and these are the guys that should be driving a number of OWASP's initiatives, since they represent the 'real-world'. Please correct me if I'm wrong, but a google and owasp search (for 'OWASP Etsy') didn't show a lot of joint activity (the best ones where Nick's participation in the AppSec USA and this job post mentioning the OWASP Top 10). It would be great to see Etsy's guys pushing projects like: AppSensor, ESAPI, Zap, Testing+Developer+Code-Review guides, O2, Exams/Certification, etc...
We (OWASP) need to find ways go get these guys more involved and put them on the driving seat.
In fact, for the next OWASP Summit, we have to make sure these guys are there, working collaboratively with the best minds in Application Security :)
Labels:
OWASP MIA
Tuesday, 30 October 2012
The next level App Security Social Graph
My core belief is that openness and visibility will eventually create a model/environment where the 'right thing' tends to happen, since it is not sustainable (or acceptable) to do the 'wrong thing' (which without that visibility is usually not exposed and contested). See the first couple minutes on the Git and Demoracy presentation for a real powerful example of this 'popular/viral awareness' in action.
When I look at my country (Portugal and now UK) or my industry (WebAppSec) I see countless examples of scenarios where if information was being disclosed and presented in a consumable way, A LOT of what happens would not be tolerated.
For example, we (in WebAppSec) industry know how bad the software and applications created every day are. And we (and the customers) have accepted that vulnerabilities are just part of creating software, and that the best we can do is to improve the SDL (and reduce risk).
But, if the real scale of the problem was known, would we (as a society or industry) accept it? Would we accept that large parts of our society are built on top of applications that very few people have any idea of how they work? (might as well if they are secure).
So while OWASP is busy booking meetings to have meetings, the rest of the world is moving on, and is trying to find ways to connect data sets in a way that 'reality is understandable/visible', so that what is really going on, is exposed in a easy to consume and actionable way.
For example take a look at the Next Level Doctor Social Graph for an attempt at driving change while trying to figure out a commercially viable way of doing it (check out their '“Open Source Eventually” idea)
From that page, here is is their description of the problem:
"It is very difficult to fairly evaluate the quality of doctors in this country. Our State Medical Boards only go after the most outrageous doctors. The doctor review websites are generally popularity contests. Doctors with a good bedside manner do well. Doctors without strong social skills can do poorly, even if they are good doctors. It is difficult to evaluate doctors fairly. Using this data set, it should be possible to build software that evaluates doctors by viewing referrals as “votes” for each other." (see related reddit thread here)
This is what they call the Next Level Doctor Social Graph , and when I was reading it I was thinking about doing the same for software/apps under the title: The next level App Security Social Graph
Here is the same text with some minor changes (in bold) on what the The next level App Security Social Graph could be:
"It is very difficult to fairly evaluate the quality of software/application's security in this country. Our regulators only go after the most outrageous incidents/data-breaches. The product/services websites are generally popularity contests. Applications with a good marketing do well. Applications without strong presentation skills can do poorly, even if they are secure applications. It is difficult to evaluate security fairly. Using this data set, it should be possible to build software that evaluates application's security by viewing ..... (to be defined)"
It would be great if the current debate was on that ..... (to be defined) bit (ideally with a number of active experiments going on to figure out the best metrics) ... but we quite far away from that world ....
... meanwhile another 8763 vulnerabilities (change this value to a quantity you think is right) have just been created since you started reading this post. These 'freshly baked' vulnerabilities are now in some code repository and will be coming soon to an app that you use (and your best defence is to hope that you are not caught by its side-effects)
When I look at my country (Portugal and now UK) or my industry (WebAppSec) I see countless examples of scenarios where if information was being disclosed and presented in a consumable way, A LOT of what happens would not be tolerated.
For example, we (in WebAppSec) industry know how bad the software and applications created every day are. And we (and the customers) have accepted that vulnerabilities are just part of creating software, and that the best we can do is to improve the SDL (and reduce risk).
But, if the real scale of the problem was known, would we (as a society or industry) accept it? Would we accept that large parts of our society are built on top of applications that very few people have any idea of how they work? (might as well if they are secure).
So while OWASP is busy booking meetings to have meetings, the rest of the world is moving on, and is trying to find ways to connect data sets in a way that 'reality is understandable/visible', so that what is really going on, is exposed in a easy to consume and actionable way.
For example take a look at the Next Level Doctor Social Graph for an attempt at driving change while trying to figure out a commercially viable way of doing it (check out their '“Open Source Eventually” idea)
"It is very difficult to fairly evaluate the quality of doctors in this country. Our State Medical Boards only go after the most outrageous doctors. The doctor review websites are generally popularity contests. Doctors with a good bedside manner do well. Doctors without strong social skills can do poorly, even if they are good doctors. It is difficult to evaluate doctors fairly. Using this data set, it should be possible to build software that evaluates doctors by viewing referrals as “votes” for each other." (see related reddit thread here)
This is what they call the Next Level Doctor Social Graph , and when I was reading it I was thinking about doing the same for software/apps under the title: The next level App Security Social Graph
Here is the same text with some minor changes (in bold) on what the The next level App Security Social Graph could be:
"It is very difficult to fairly evaluate the quality of software/application's security in this country. Our regulators only go after the most outrageous incidents/data-breaches. The product/services websites are generally popularity contests. Applications with a good marketing do well. Applications without strong presentation skills can do poorly, even if they are secure applications. It is difficult to evaluate security fairly. Using this data set, it should be possible to build software that evaluates application's security by viewing ..... (to be defined)"
It would be great if the current debate was on that ..... (to be defined) bit (ideally with a number of active experiments going on to figure out the best metrics) ... but we quite far away from that world ....
... meanwhile another 8763 vulnerabilities (change this value to a quantity you think is right) have just been created since you started reading this post. These 'freshly baked' vulnerabilities are now in some code repository and will be coming soon to an app that you use (and your best defence is to hope that you are not caught by its side-effects)
Labels:
OWASP MIA
Thursday, 25 October 2012
Nice list of 20 online coding tools
There is definitely a lot of innovation happening in this space, check out the list at The top 20 online coding tools from .Net magazine.
And if we want to enable the next generation of developers to code securely we need to integrate our knowledge into their IDEs (like these ones). Humm .... I wonder how hard it will be to add TeamMentor integration to these IDEs?
Note that this is on a mainstream developer magazine and (predictably) a search for 'security' or 'owasp' has 0 hits on that page:
And if we want to enable the next generation of developers to code securely we need to integrate our knowledge into their IDEs (like these ones). Humm .... I wonder how hard it will be to add TeamMentor integration to these IDEs?
Note that this is on a mainstream developer magazine and (predictably) a search for 'security' or 'owasp' has 0 hits on that page:
Sunday, 21 October 2012
Let's make this happen: "Investing in Developing Software Security Talent"
Mark posted yesterday an 'draft' idea which I think is GREAT!
Please read it at Investing in Developing Software Security Talent
Although I think that Mark is on a great path, one that is consistent with his views of bringing developers to security (not security to developers), I have a couple comments on is proposed model :)
Here are my key proposed changes:
This is how I would slice it:
Master version (the 'code'): "Developing Software Security Talent" Programme:" - Improving the Software Security Talent of a new Generation of Software developers and 'code fixers'.
The focus of this program is to help Developers or Security Professionals who want to write secure code or fix security vulnerabilities. The model proposed is one based on Internships and Mentorships.
Fork #1 (the 'data) "Seconauts participation in "Developing Software Security Talent" Programme:
Seconauts will:
Fork #2: XYZ Company ....
Fork #3: XYZ University ....
Fork #4: UK Government ....
Fork #5: OWASP ....
etc...
Remember that the objective is to develop Security Talent, so it doesn't really matter how it is done, as long as it happens.
It is also important to take into account that some companies or organisations have a 'Not invented here' syndrome, and it is important to present them with ideas that they can consume, re-brand and execute
Rough/Draf notes
Since Mark's original post was in a 'Draf' mode', here are a bunch of semi-related notes and ideas that I had when reading and thinking about this.
Starting with some comments on the proposed model, I'm going to use SI (Security Innovation) as an example of a company that could participate on the mentoring and hiring activities (note that I have not spoken with the SI guys about this, it is just easier to have a specific example in mind):
Bottom line: Good luck Mark
More Secure Coding talent is something we desperately need, so I hope that this idea really comes into life and I'm happy to help as much as I can.
Why I have experience in making this comments
(originally I had this at the beginning of the post, but I figured out, that this will only be relevant to the readers that are reading it all the way to the end):
-----------------------------------------------------------------------------
I'm going to comment on this as somebody who as already implemented a similar program at OWASP namely the OWASPs Seasons of code who had a similar number of moving parts and activities:
I was also very involved with Paulo Coimbra and the GPC on the management of OWASP projects, where we did a lot of thinking about this:
Please read it at Investing in Developing Software Security Talent
Although I think that Mark is on a great path, one that is consistent with his views of bringing developers to security (not security to developers), I have a couple comments on is proposed model :)
Here are my key proposed changes:
- Separate the 'creating security talent' from Seconauts (ie 'separate code from data', or using a git analogy 'fork the main repository')
- Expand the concept to include current Developers and Security Professionals
- Create a financial model that is easy to implement, transparent and morally effective
This is how I would slice it:
Master version (the 'code'): "Developing Software Security Talent" Programme:" - Improving the Software Security Talent of a new Generation of Software developers and 'code fixers'.
The focus of this program is to help Developers or Security Professionals who want to write secure code or fix security vulnerabilities. The model proposed is one based on Internships and Mentorships.
- The key objective is to create the next generation of developers who will:
- know how to write secure code,
- work with the multiple SDL parties in the multiple secure coding/architecture activities and
- fix security vulnerabilities
- The program will measure its success by the number of 'conversions' made over a period of time:
- # of students that are now focus on secure coding
- # of real-world developers who have added 'secure coding' to their skill set
- # of developers (and job applications) that have 'secure coding' on its job spec
- # of Application Security professionals who have acquired 'secure coding' skills and can talk with developers (in the developer's language) and are able (when requested) to sit down and fix code
- A desired site-effect is the creation of an open community and 'high-quality body of work', that supports the millions of developers who need to write secure code worldwide, and ask 'secure coding questions' everyday.
- How these 'conversions' are made, is not an important detail:
- The 'Seconauts model' (descibed below) is just one way to achieve this goal
Fork #1 (the 'data) "Seconauts participation in "Developing Software Security Talent" Programme:
Seconauts will:
- Find the sponsors and mentors
- Handle the logistics (from payments, to selections, to contacts, to introductions, to public reporting, etc..)
- Define the selection criteria, select the candidates and allocated them to the mentors
- Define the Seconauts projects that will be worked on (by the candidates) and ensure that there is enough high-quality reviewers at hand to help with task allocation and questions raised (by the candidates)
- Help and brief the Mentors (with clear definitions of what are the expectations and responsibilities of each party)
- ...see mark's post for a specific details (like the number of mentors, what each one should do, etc...)
Fork #2: XYZ Company ....
Fork #3: XYZ University ....
Fork #4: UK Government ....
Fork #5: OWASP ....
etc...
Remember that the objective is to develop Security Talent, so it doesn't really matter how it is done, as long as it happens.
It is also important to take into account that some companies or organisations have a 'Not invented here' syndrome, and it is important to present them with ideas that they can consume, re-brand and execute
Rough/Draf notes
Since Mark's original post was in a 'Draf' mode', here are a bunch of semi-related notes and ideas that I had when reading and thinking about this.
Starting with some comments on the proposed model, I'm going to use SI (Security Innovation) as an example of a company that could participate on the mentoring and hiring activities (note that I have not spoken with the SI guys about this, it is just easier to have a specific example in mind):
- I think that the amount paid to the 'candidate' should 'be defined' by the 'contracting party', in this case SI. Since SI would want to get the best talent, it can chose to pay more (this will also depend on the geographical location of the candidate)
- Although I'm a big believer of openness, in this case, the 'financial arrangement' should be a private matter between SI and the candiate
- I like the ideas to give the candidate some money, but this should ONLY be used to cover expenses (computer equipment, travel, hosting services, software, etc). In a similar way that I wrote on Why OWASP can't pay OWASP Leaders the moment the sponsorship money is used as 'payment to the candidate' the social contract between the organisation, the mentors and its participants is broken:
- See previous point on how I'm NOT saying that the candidate should NOT be paid
- I'm saying that the candidate SHOULD be paid, just not by this program (whose funds should only be used for 'expenses')
- With this in mind, the candidate should be given $4000, where HE/SHE decides where to spend that money (and in time there would be a good number of documented examples of where others spent it)
- Like I wrote in the problem of paying OWASP leaders and in the OWASP GSD Project (GSD = Get Stuff Done) proposal, the concept is one where the candidate cannot NOT pay himself, or any company/individual he/she is associated with (this is a great self-regulated system, and it would dramatically reduce the management, monitoring and 'expense approval' requirements / overhead)
- This can be easily executed on a worldwide basis as long as the pieces are in place
- I don't think that the 'need for the candidate to go everyday' to an office is a critical one.
- It raises the bar and complexity of the arrangement
- It goes against the model of the 'distributed' development environment that we have today in the 'GitHub' generation
- Development is sometimes better done in isolation than in groups
- Again, not saying that it shouldn't happen, just that it shouldn't be a big criteria
- For example I have no idea of where some of my good colleagues at SI are (even when I talk to them by voice, email, github, code everyday). They could be somewhere in Europe , in the Boston or Seattle offices or in the middle of the US)
- So I would change this requirement to be 'the candidate must have a physical connection with the mentors every week, which could range from hours to 5 days'
- If the cost allocated to each candidate is $4000, then the sponsorship packages should be multiples of that:
- $4k pays for 1
- $8k pays for 2
- $12k pays for 3
- $20k pays for 5 .... etc...
- This could be set-up on a recurring basis so that the sponsoring companies could view it as a recurring subscriptions.
- I think that there should be NO requirement on either party regarding the next contracts (i.e. namely no obligation for the candidate to work 18 months for the mentoring company).
- For example I would expect that if a candidate did a successful internship at SI, and he liked SI that he wanted to join the company, and SI liked his/her work so much that it would offer a job:
- there would be no need for a 'mandatory 18 months contract'
- the contract offerend by SI should be competitive and fair ,
- such '18 months requirement to work for SI' would dramatically change the negotiation dynamics (putting a lot of power in the hands of SI) and would most likely leave a bitter taste in everybody involved
- The focus should be on writing secure code and fixing existing code at Open Source projects, BUT we shouldn't have very high hopes that the code created will be of a very high standard since by definition these are inexperience 'secure development' developers (which will take more than 6 months to change)
And here is a brain dump of 'stuff' that needs some more thinking:
- it is going to be hard to find a significant number of mentors (which is a catch 22 ,since once the model is proven, they will be easier to find)
- I would say that this is the hard part. At OWASP's Projects (see links below) we had a simpler workflow (which was project leader working with 2 reviewers) and it was REALLY hard to get good reviews created (it does take a lot of time to review something properly). I don't think it should be underestimated how much effort it will take from the mentors and helpers
- There is usually a great difference between the amount of people who will put their hand up and say 'I can do it, I can review that or mentor him/her' to the ones who will actually be able to do it (and sometimes it is not that the reviewer/mentor are not good enough, it is just that it takes a lot of time and effort to do it properly)
- Creating a selection criteria and executing it will be hard, and the best way is to do it 100% in the open (learn from the OWASP seasons of code experience (see links below))
- Expand the target audience (it should also be focused on current professional developers that want to get into application security). We need this NOW for developers that are coding today:
- In fact most companies that write a lot of software need this TODAY for a number of their current dev teams
- I don't like the word 'intern' is sounds like it is for a somebody leaving school (or university). This is why I used the word 'candidate' on this post.
- ex-students should be only one of the target audiences
- The work created by the 'candidates' is most likely NOT going to be production quality (since by default they will be amateurs at it). Only experienced developers (with security awareness/knowledge) are able to create that. So let's not raise the expectations bar too high
- Mark's maths are wrong:
- $4000 will be barely enough to buy: a decent laptop, airfare expenses, hotels, hosting, software,etc... (over a period of 6 months). It will help if outside the US/UK, but we are talking about 800 USD per month (which is less than you get flipping burgers)
- It also doesn't take into account all the back-office admin costs that it will take to make this happen (which I agree that shouldn't be paid from the $4000 sponsorship money)
- I like this idea as a good way to get talent to work on Seconauts (but i can see some critics saying that this is just a cheap way to kickstart a community)
- This is very similar to what happens on a number of companies, and it is called 'Interns' :)
- in fact a number of OWASP members have such programs at their companies (which could be leveraged to kickstart this idea)
- This will not work without operational support/staff, in fact the first thing to do should be to hire / appoint a project manager to run this (Mark is currently doing that role, but he will soon run out of time/energy)
- There is already lot of mentoring happening at OWASP and I am personally involved in a couple of mentoring cases (not within an explicit framework, but achieving the same goals). So some of those efforts could be recycled to kickstart this idea
- There are already a good number of targets for mentorship at OWASP, namely some newer OWASP leaders who are still getting their heads around WebAppSec
- The irony is that OWASP would be the perfect place to do this, since it has the infrastructure, the funds, the community, the brand, etc...
- That said, I think the concept is great, and since Mark is focused on it (and nobody is at OWASP), I will ask the Owasp community to support it and commit to at least 10k. I also will raise this idea at SI and see if they would like to participate
Bottom line: Good luck Mark
More Secure Coding talent is something we desperately need, so I hope that this idea really comes into life and I'm happy to help as much as I can.
Why I have experience in making this comments
(originally I had this at the beginning of the post, but I figured out, that this will only be relevant to the readers that are reading it all the way to the end):
-----------------------------------------------------------------------------
I'm going to comment on this as somebody who as already implemented a similar program at OWASP namely the OWASPs Seasons of code who had a similar number of moving parts and activities:
- Autumn of Code 06,
- Spring of Code 07,
- Summer of Code 08 (whose results were presented at first OWASP Summit 2008)
I was also very involved with Paulo Coimbra and the GPC on the management of OWASP projects, where we did a lot of thinking about this:
- https://www.owasp.org/index.php/Assessment_Criteria_v1.0 (more mature model)
- https://www.owasp.org/index.php/Assessment_Criteria_v2.0 (note how at the end of this page there is a reference to Project Mentors (there was more on mentoring concept, but I couldn't easily find that page/info))
- https://www.owasp.org/index.php/Tool_Assessment_Criteria
- https://www.owasp.org/index.php/Documents_Assessment_Criteria
- https://www.owasp.org/index.php/Research_and_Activities_Criteria
- https://www.owasp.org/index.php/Assessing_Project_Health
- https://www.owasp.org/index.php/Assessing_Project_Releases
For reference, before Paulo Coimbra left OWASP, we were really close to implementing a similar program at OWASP (the idea was to start with getting reviewers involved into projects (in a 'Season of Quality') and then evolve it into mentorships).
And has Paulo's departure showed, without such back-office support it is impossible to do this.
Btw, to give you an idea of the amazing work Paulo was doing on OWASP projects, take a look at https://www.owasp.org/index.php/OWASP_Projects_Dashboard_2.0 (you will be amazed). The good news is that we now have Samantha (Owasp new project manager) who is going to bring things back on track
Labels:
OWASP MIA
Friday, 12 October 2012
'Using the HTML5 Fullscreen API for Phishing Attacks', OWASP MIA and 'We need SAST technology for browsing the web safely'
Really nice article from Feross Aboukhadijeh on the Phishing potential of HTML5 FullScreen features:
You can read it at Using the HTML5 Fullscreen API for Phishing Attacks
Note that on Chrome in OSx it will show this alert
... if you're not in Full Screen already. But in a lot of cases that will be easy to dismiss (specially with users used to click that 'Allow' button). See note below on using SAST technology to deal with this.
What is interesting about this story is that is also shows how developers DO care about security. There is a thread about it on Hackers News and on Reddit and I found this article via the CodeProject's Daily New email:
OWASP MIA
But where's OWASP on this thread?
So is Feross involved at all with OWASP? I can't find it.
As one of the guys who created one of the best ClickJacking examples HOW TO: Spy on the Webcams of Your Website Visitors (and only 22 years old), he is clearly part of the new generation of AppSec Security experts.
But if OWASP is not able to attract him and create environments / ecosystems for Feross (and other new stars), that means that we (OWASP) are starting to be irrelevant for the new Generation :(
And that is a fundamental problem with OWASP. We should be measuring OWASP's success by its community and relevance. But it is much harder to measure 'What could had happened' than 'what is happening'. This (amongst others) is why I proposed a new model for OWASP so that OWASP can reinvent itself and find ways to add value to Feross (and its community).
We need SAST technology for browsing the web safely
So how to do solve this? Unless we start to have SAST-like Technology on browsers (which allow us to write context-sensitive rules that know the difference between YouTube and Feross' website) I don't think we will find a good solution (it's just patches and hacks)
You can read it at Using the HTML5 Fullscreen API for Phishing Attacks
Note that on Chrome in OSx it will show this alert
... if you're not in Full Screen already. But in a lot of cases that will be easy to dismiss (specially with users used to click that 'Allow' button). See note below on using SAST technology to deal with this.
What is interesting about this story is that is also shows how developers DO care about security. There is a thread about it on Hackers News and on Reddit and I found this article via the CodeProject's Daily New email:
OWASP MIA
But where's OWASP on this thread?
- both Hackers News and on Reddit have no mention for OWASP (just search the page)
- Feross article also has no mention of OWASP
- A quick search for Feross' name and OWASP didn't show anything
- Nothing on OWASP's website (which means that he has not presented at an OWASP conference or chapter)
So is Feross involved at all with OWASP? I can't find it.
As one of the guys who created one of the best ClickJacking examples HOW TO: Spy on the Webcams of Your Website Visitors (and only 22 years old), he is clearly part of the new generation of AppSec Security experts.
But if OWASP is not able to attract him and create environments / ecosystems for Feross (and other new stars), that means that we (OWASP) are starting to be irrelevant for the new Generation :(
And that is a fundamental problem with OWASP. We should be measuring OWASP's success by its community and relevance. But it is much harder to measure 'What could had happened' than 'what is happening'. This (amongst others) is why I proposed a new model for OWASP so that OWASP can reinvent itself and find ways to add value to Feross (and its community).
We need SAST technology for browsing the web safely
So how to do solve this? Unless we start to have SAST-like Technology on browsers (which allow us to write context-sensitive rules that know the difference between YouTube and Feross' website) I don't think we will find a good solution (it's just patches and hacks)
Labels:
OWASP MIA
Tuesday, 9 October 2012
Great animation that shows how BootStrapToday works
Checkout this video that I found on the the http://bootstraptoday.com/ homepage:
Labels:
OWASP MIA,
Visualization
Saturday, 2 June 2012
Big Security challenges with creating APIs for US Gov agencies
So Barack Obama Directs All Federal Agencies to Have an API
Here is the White house memo (pdf) which mandates the implementation of "Digital Government: Building a 21st Century Platform to Better Serve the American People" (pdf).
The good news it that at least security and privacy seems to be taken into account (with it's own chapter and focus)
I haven't read the document but after a skim, it looks like there is more focus on the non-secure-application-development 'security side' of these APIs.
And this could be an issue, since creating APIs is usually done by exposing internal systems or WebServices, which will now need to have much higher level of security than before (when they were connected to much less hostile environment).
I also like the use/focus on Privacy, since that will be a good way to drive coding and application changes.
This is a great opportunity for OWASP community to be involved since there is going to be a lot of API developers out there that could do with some help
Here is the White house memo (pdf) which mandates the implementation of "Digital Government: Building a 21st Century Platform to Better Serve the American People" (pdf).
The good news it that at least security and privacy seems to be taken into account (with it's own chapter and focus)
I haven't read the document but after a skim, it looks like there is more focus on the non-secure-application-development 'security side' of these APIs.
And this could be an issue, since creating APIs is usually done by exposing internal systems or WebServices, which will now need to have much higher level of security than before (when they were connected to much less hostile environment).
I also like the use/focus on Privacy, since that will be a good way to drive coding and application changes.
This is a great opportunity for OWASP community to be involved since there is going to be a lot of API developers out there that could do with some help
Labels:
OWASP MIA
Friday, 11 May 2012
To read: ENISA on 'National Cyber Security Strategies'
On May 08, 2012 ENISA published an National Cyber Security Strategies paper which the current status of cyber security strategies.
Here is their desciption:
"..The paper includes a short analysis of the current status of cyber security strategies within the European Union and elsewhere. It also identifies common themes and differences, and concludes with a series of observations and recommendations. The paper is based on the preliminary findings and analysis from an ENISA project that is working to develop a Good Practice Guide on how to develop, implement and maintain a national cyber security strategy. The Good Practice Guide is intended to be a useful tool and practical advice for those responsible and involved in cyber security strategies...."
"..The paper includes a short analysis of the current status of cyber security strategies within the European Union and elsewhere. It also identifies common themes and differences, and concludes with a series of observations and recommendations. The paper is based on the preliminary findings and analysis from an ENISA project that is working to develop a Good Practice Guide on how to develop, implement and maintain a national cyber security strategy. The Good Practice Guide is intended to be a useful tool and practical advice for those responsible and involved in cyber security strategies...."
Here is the PDF, any comments?
Btw, I had a quick look and found no reference to OWASP, shouldn't we be involved here? Or does Cyber-Security has nothing to do with Application Security?
Friday, 27 April 2012
Hack Yourself First: Jeremiah at TEDxMaui
Jeremiah was recently at TEDxMaui presenting Hack Yourself First which is an interesting development for WebAppSec and OWASP since I think it is the first time that a member of our community gets to present at TED (which is one of the best conference-series in the world)
Couple comments:
Couple comments:
- he was quite nervous, which shows the 'pressure to deliver' that TED has.
- See Jeremiah's Written Speech (i.e. what he wanted to say) and his personal comments about the experience)
- I really like the concept of 'Hack yourself first' but I wished Jeremiah had given more examples on how to do it an a personal, corporate and organisational level
- there was FAR too much FUD for my taste. I would had been better if he found a more positive way to deliver the message
- It is also quite obvious by Jeremiah performance that he really cares about WebAppSec and wants to make the world more secure
- Of course that he owns a company that helps companies to 'Hack themselves first' so there is a lot of vested interest in there too :)
- I think that OWASP doesn't get one mention, which is not Jeremiah's fault. I just shows the weakness of the OWASP Brand
Here is the Video:
Labels:
OWASP MIA,
Philosophy,
Security
Trustworthy Internet Movement and SSL Pulse
Ivan's interesting work at Qualys continues with the launch of the Trustworthy Internet Movement (TIM) and SSL Pulse at RSA.
There are a number of interesting developments here:
There are a number of interesting developments here:
- Great presentation and message
- Real nice project page for SSL-Pulse: https://www.trustworthyinternet.org/ssl-pulse/
- Good funded project: Its looks like they started with 500k USD investment from Philippe Courtot
- Some efforts at creating a community (with a Join the Movement) although it doesn't say what happens next
- Reuse of Ivan's SSL Labs great work gives this 'Movement' a good momentum
- Now look at they fundamentals ('Innovation, Collaborate, Individual Expertise'), principle ('TIM’s mission is to resolve major lingering security issues on the Internet, such as SSL governance and the spread of botnets and malware, by ensuring security is built into the very fabric of private and public clouds, rather than being an afterthought.') and Target Audience ('Experts, Innovators and Technical gurus, Stakeholders, Corporations, Academic institutions and non-profit organizations, Angel investors and VCs')
- Quite a targeted audience
- Will be interesting to see who joins and provides financial backing
- Its quite SSL focused, there is a lot more to cloud security than SSL :)
- No reference to openness :)
- It sounds a lot like the model Mark Curphey wishes OWASP would follow :)
So at the moment this is basically a good Qualy's branding exercise, and will help a bit to improve the WebApp security world, but the key question is if there will be community adoption/participation and if others will join the party.
There is nothing wrong with what Qualys is doing, and the fact that this investment (on Application Security) is happening outside of OWASP shows that OWASP doesn't currently have a model/structure that promotes this type of collaboration. And that is very unfortunate, since in terms of worldwide community and reach there is SO much OWASP could do to help this type of initiative.
Blogger in HTTP only? What happened to HTTPS?
UPDATE (2016): Blogger has limited support for https, see https://security.googleblog.com/2016/05/bringing-https-to-all-blogspot-domain.html
Now that I'm blogging more, I'm finding the need to blog from insecure locations (like a coffee shop or conference).
But unfortunately it doesn't seem to be possible to use SSL with Blogger? WTF! in 2012?
After this 2009 letter Google moved some of its web apps to SSL (see Google's answer at HTTPS security for web applications) but blogger seems to have been missed!
At the moment it doesn't seem to be a way to write a blog post (like this one) without risking my sessionID being compromised. Am I missing something obvious?
Here is are thread Can I use an HTTPS connection for editing and posting on Blogger? (which points to a non-existing thread) that implies that Google doesn't do this due to performance issues.
Also annoying is the fact that https://diniscruz.blogspot.co.uk/ doesn't work! So how can I know that this blog's content is read as it was written (ie. without its content being tampered with)
On the topic of OWASP, note how there is no mention to it on the letter. Yes this letter is from 2009 but if it was written today, would OWASP be there? (this is what I'm now calling OWASP MIA (Missing In Action))
On that topic, why don't we write another letter to Google asking for them to extend their security efforts into blogger!
Also, if Google doesn't care about this and give us no solution, what other options do we have? What about a 'cloud' service that gives me secure access to this blog?
Now that I'm blogging more, I'm finding the need to blog from insecure locations (like a coffee shop or conference).
But unfortunately it doesn't seem to be possible to use SSL with Blogger? WTF! in 2012?
After this 2009 letter Google moved some of its web apps to SSL (see Google's answer at HTTPS security for web applications) but blogger seems to have been missed!
At the moment it doesn't seem to be a way to write a blog post (like this one) without risking my sessionID being compromised. Am I missing something obvious?
Here is are thread Can I use an HTTPS connection for editing and posting on Blogger? (which points to a non-existing thread) that implies that Google doesn't do this due to performance issues.
Also annoying is the fact that https://diniscruz.blogspot.co.uk/ doesn't work! So how can I know that this blog's content is read as it was written (ie. without its content being tampered with)
On the topic of OWASP, note how there is no mention to it on the letter. Yes this letter is from 2009 but if it was written today, would OWASP be there? (this is what I'm now calling OWASP MIA (Missing In Action))
On that topic, why don't we write another letter to Google asking for them to extend their security efforts into blogger!
Also, if Google doesn't care about this and give us no solution, what other options do we have? What about a 'cloud' service that gives me secure access to this blog?
Subscribe to:
Posts (Atom)



