Comments
rlebherz wrote: Alf, Interesting article. I think the Cloud services and cloud infrastructure lines are a bit blurred, but I agree with most of what you are saying. Dont underestimate the SLA's role in accountability. For companies that have dynamic requirements and no down time can be afforded, make sure you have very tight SLAs. For example, OpSource provides a 100% SLA in the cloud and 100%SLA around production application environments. Now 100% is ideally perfect, it comes down to accountability, yo...
Cloud Expo on Google News

SYS-CON.TV

2008 West
DIAMOND SPONSOR:
Data Direct
SOA, WOA and Cloud Computing: The New Frontier for Data Services
PLATINUM SPONSORS:
Red Hat
The Opening of Virtualization
GOLD SPONSORS:
Appsense
User Environment Management – The Third Layer of the Desktop
Cordys
Cloud Computing for Business Agility
EMC
CMIS: A Multi-Vendor Proposal for a Service-Based Content Management Interoperability Standard
Freedom OSS
Practical SOA” Max Yankelevich
Intel
Architecting an Enterprise Service Router (ESR) – A Cost-Effective Way to Scale SOA Across the Enterprise
Sensedia
Return on Assests: Bringing Visibility to your SOA Strategy
Symantec
Managing Hybrid Endpoint Environments
VMWare
Game-Changing Technology for Enterprise Clouds and Applications
Click For 2008 West
Event Webcasts

2008 West
PLATINUM SPONSORS:
Appcelerator
Get ‘Rich’ Quick: Rapid Prototyping for RIA with ZERO Server Code
Keynote Systems
Designing for and Managing Performance in the New Frontier of Rich Internet Applications
GOLD SPONSORS:
ICEsoft
How Can AJAX Improve Homeland Security?
Isomorphic
Beyond Widgets: What a RIA Platform Should Offer
Oracle
REAs: Rich Enterprise Applications
Click For 2008 Event Webcasts
Multiple Twitter Worms Shows Need to Incorporate Security
When it comes to security, or rather, the lack of it, Web 2.0 has become a deja vu for the early days of the Internet

The fact that Twitter has been hit by as many as four worms over the Easter weekend highlights the need to include the code audit and security process in the software development cycle, says Fortify Software, the application vulnerability specialist.

"Media reports have made much about the author of what appears to be the first generation of Twitter worms, but they appear to have missed the point that these are actually basic cross-site scripting (XSS) security problems," said Barmak Meftah, Fortify Software's senior vice president of products and technology.

"The situation acts as yet another reminder that code vulnerability exploitation is now sufficiently high up the hacker agenda to warrant the inclusion of code auditing in the software planning and development process," he added.

According to Meftah, the axiom of a company taking its security seriously is no longer proven if the firm fixes problems after they take place.

This Twitter hack, he says, is a classic example of how poor coding enables cracking situations that should never have been allowed to happen in the first place.

There is, he explained, no excuse for poor coding, even with free software.

"Twitter claims they've solved it, but this hard to believe.  If you can find 4 vulnerabilities in 48 hours, this indicates a bigger problem.  This highlights a common issue--developers rapidly writing code with minimal auditing and few security checks," added Meftah.

"When it comes to security, or rather, the lack of it, Web 2.0 has become a deja vu for the early days of the Internet," he said.

About Web 2.0 News Desk
The Web 2.0 Journal News Desk keeps you up to speed with all that's happening in the world of the read/write Web and all its mushrooming new facets - from tagging, wikis, mash-ups, and image-sharing to "Advertising 2.0," podcasting, and The Writeable Web.

In order to post a comment you need to be registered and logged in.

Register | Sign-in

Reader Feedback: Page 1 of 1

Latest AJAXWorld RIA Stories
The world’s most powerful supercomputer is Jaguar, the recently upgraded Cray XT5 rig at Oak Ridge National Laboratory in Tennessee, according to the new semi-annual Top500 list. Jaguar’s roughly 250,000 processors went from quad-core Opterons to six-core Istanbul Opterons and no...
I read an article by an author on Ulitzer.com and was amazed at the professional image it provided him. I immediately researched Ulitzer to see if there was yet hope for me. I am a technology blogger on the subject of mobile computing strategies. As I was doing research I came a...
CIO and CTO salaries will see a spike of 12.5% in 2010, according to research conducted by Bluewolf on salaries in the Tri-state region (New York, Conn. and New Jersey). Bluewolf is a global technology consulting firm and the preeminent source of salary data and statistics for IT...
The rise of RIAs and cloud computing, and the increased diversity of Internet-connected devices are spawning the need for contextual applications that take advantage of specific functionality offered by operating systems and devices. The Flash Platform enables developers to creat...
In the first code challenge of its kind, Visual WebGui is offering a $10,000 and giving away prizes valued at thousands of dollars in their call to developers to be the first to submit a Webmail application written by another framework with fewer lines of code. Developers can reg...
Subscribe to the World's Most Powerful Newsletters
Subscribe to Our Rss Feeds & Get Your SYS-CON News Live!
Click to Add our RSS Feeds to the Service of Your Choice:
Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
Publish Your Article! Please send it to editorial(at)sys-con.com!

Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021


SYS-CON Featured Whitepapers
ADS BY GOOGLE