On TechRepublic: Weirdest error messages of all time
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 9 of 23:
Next »
« Previous
"Good luck" as security strategy
Over the past 2 years I came across a number of similar cases like these on major websites. What is worse is the attitude that most of the operators demonstrate when you point the finger onto the flaws.

Without any hacking attempts (or knowledge, for the matter) I accidentially downloaded an entire database with detailed information about users, addresses and their calls from the public website of Winstar. All it took was to type in a search term into the povided search box. They never even bothered to fix the hole (and finally went out of business). Just 2 weeks ago, I alerted Ebay about a fairly clever credit card phishing attempt by a Swiss company, delivered the name, phone number, address, website etc. to Ebay's fraud department. After a week, the site was still online, a second attempt to contact Ebay was as fruitless as the first (no response at all), only after I contacted PayPal they started some action. So much about Ebay's dedication to combat fraud...Tower Records recently got fined for not fixing security holes after they were alerted about them, Covad's online account manager was not even encrypted (any cheap hosting account provides better security then this!), a US Healthcare company enabled me to break into their entire client database without any particular skills ( this got fixed later) etc. etc.

It is my job to build web applications, so maybe I tend to look a bit more closely at the details. However, none of the above examples involved any special skills, coding capabilities, backdoors, DDoS attacks, brute force attacks, exploiting of buffer overflows or publicly knows vulnerabilities etc. None of them even required particular talent to get fixed by the companies. But they required some action.

I always explain to clients the importance of not only designing a secure system, but also testing it extensively before a launch and monitoring is afterwards. Of course, in the meeting they always approve everything "Yes!Yes!Yes!" - until the next budget request comes in. Reality is that the all-mighty "Return on investment" and "Time to Market" is the best guarantor that systems will sooner or later fail, simply because the development team is not given the necessary means to develop and test it properly from all the angles that a creative hacker (or a clueless lucky/unlucky user) will probably approach it from.

When large players like Cingular demonstrate such a degree of ignorance and arrogance for the privacy of their customer information, there is truly no excuse. They have the money & means to build good systems & interfaces, and compared to the funds that they spend on advertising and their exec's top salaries, the effective costs would be ridiculously small.

On the other hand, software developers are also partly to blame for not being more responsible (or aware) of the complexity and vulnerabilities of online web-based e-commerce and CRM applications, and for not insisting on more extensive Q/A. Unfortunately, especially on the lower end of software projects, the competition among developers often leads to underfunded projects and irrealistic development times - simply for the sake of "getting the job". But I doubt that this was the case in this example.

MG
Posted by: mgfint   Posted on: 06/09/04 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Verizon  donald17 | 06/09/04
Cellular One became Verizon  equack | 06/14/04
Maybe BITS of Cell One became Verizon  flatliner | 07/05/04
website & cs need help too!  TurboFord | 06/09/04
verizon user  elainecleo | 06/09/04
Verizon net access  ConnieKelly | 06/09/04
"Good luck" as security strategy  mgfint | 06/09/04
Quis custodiet  JelM | 06/11/04
"Good luck" as security strategy  mgfint | 06/09/04
Cingular System Frailty  joehughes12 | 06/09/04
We should next read about....  BitTwiddler | 06/09/04
There's any number of reasons for this...  Taz_z | 06/09/04
Spokesperson-ese - UGH  relictele | 06/09/04
The real problem is convenience  Squawkbox | 06/09/04
cingular  motoman1 | 06/09/04
Re: cingular  El.Gato@... | 06/10/04
Stay away from these thieves  ArtyChoked | 06/10/04
Security breaches, not of the technology kind  david_hobbs@... | 06/11/04
Security breaches on phones  mlrome@... | 06/14/04
Drop Cingular  jhimes | 06/15/04
A practical suggestion  thomgood | 06/12/04
Sounds like a "Feature", not a bug.  jrbeaman | 06/15/04
Someone who has the correct information..................  cing emp | 08/09/05

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Meet Doc