13 Feb 2006
Hosted web applications could soon become a target for e-criminals as they gain in popularity among enterprise users, a security expert warned last week.
Marc Maiffret, co-founder and chief hacking officer of enterprise security specialist eEye, said that because hosted applications are run by a third party, research firms are not able to audit that software for vulnerabilities.
“The [developers] can be well-intentioned to write the most secure software possible but they will still miss things,” Maiffret argued. “With hosted applications the good guys, the researchers, can’t proactively go out and find fixes [for any flaws] but the bad guys are still out there, so there is an imbalance.”
Ross Brown, eEye’s chief operating officer, added that the nature of hosted services means that an attack’s impact would be significant. “Unlike on-premises products where every [enterprise] has a version, web services are centralised and monolithic, so if one gets compromised everyone is affected,” he said.
Meanwhile, Maiffret argued that many corporate networks are still inadequately secured, due to a lack of resources and training. “There is always a huge disconnect between how IT managers view the state of their network and the IT people, who know where they are lacking in resources,” he said. “These organisations often lack a clear understanding of whether or not the product of choice can successfully solve [their security problems] in a real-world environment.”
Have your say on this article
Newsletters
Latest stories from Security Technology
Latest videos
You may also like
Security Technology jobs
Technology Patent Wars
Case studies from large organisations across all sectors
... And rich media, and flexible working, and peaks in traffic ...
Upcoming Events
Join us for this Computing web seminar, in which the Head of BI at the Co-operative Group Nick Colebourn will be explaining just how he reigned in the Group’s sprawling database estate and how significant savings were realised and data quality improved as a result.
Date: 31 May 2012
Time: 11:00 AM
Live June 13th 11:00am: Register now. During this web seminar we will be looking at the sorts of incidents that can bring data centres grinding to a halt and what can be done about them.
Date: 13 Jun 2012
Time: 11:00 am
Receive the latest jobs direct to your inbox
Are you being paid what you are worth?