Application Mashups Require Strong Security Approach

Application Mashups Require Strong Security Approach

Forrester Research analyst Mike Gualtieri worries that developers are not adequately accounting for third-party services and APIs in their threat modeling of Web applications. “Developers are not adjusting,” he said. “They are just passing credentials and not worrying about it.”

Several experts offer suggestions for dealing with the additional threats posed by today’s mashup applications. For example, Max International CTO Jeff Hanson explains the need for client-side and server-side validation frameworks that compliment each another. “Because client-side validation can be circumvented quite easily, a comprehensive and complementary server-side validation provides another crucial component for protecting data and processes.”

Benjamin Jun, vice president of technology at Cryptography Research, adds that authentication becomes a greater challenge in mashups: “First, the enrollment process for credentials on a social networking Website is very different from getting enrollment credentials for online banking. This means that there may be gaps in trust across authentication systems. Secondly, identity and access management is complex – particularly when considering the three R’s of corner cases: redirects, renegotiation and reconnections. Developers who use authentication API’s are usually forced into using their partner’s API, but can try to avoid (or at least take great care) when using those modes.”

View article

Share the Post:
Heading photo, Metadata.

What is Metadata?

What is metadata? Well, It’s an odd concept to wrap your head around. Metadata is essentially the secondary layer of data that tracks details about the “regular” data. The regular

XDR solutions

The Benefits of Using XDR Solutions

Cybercriminals constantly adapt their strategies, developing newer, more powerful, and intelligent ways to attack your network. Since security professionals must innovate as well, more conventional endpoint detection solutions have evolved

AI is revolutionizing fraud detection

How AI is Revolutionizing Fraud Detection

Artificial intelligence – commonly known as AI – means a form of technology with multiple uses. As a result, it has become extremely valuable to a number of businesses across

AI innovation

Companies Leading AI Innovation in 2023

Artificial intelligence (AI) has been transforming industries and revolutionizing business operations. AI’s potential to enhance efficiency and productivity has become crucial to many businesses. As we move into 2023, several