Note: this blog is a mirror of my HP Labs Blog, on the same topic, accessible at: http://h30507.www3.hp.com/t5/Research-on-Security-and/bg-p/163
Showing posts with label threats. Show all posts
Showing posts with label threats. Show all posts

Monday, October 29, 2007

New ENISA Position Paper: Security Issues and Recommendations for Online Social Networks

ENISA has recently released a position paper, called “Security Issues and Recommendations for Online Social Networks” (available online, here) – Editor: Giles Hogben (ENISA):

“This paper aims to provide a useful introduction to security issues in the area of Social Networking, highlight the most important threats and make recommendations for action and best practices to reduce the security risks to users.”

Specifically, it focuses on the following threats and recommendations:

  • Principal Threats: privacy related threats, information security threats, identity related threats and social threats);
  • Recommendations and Countermeasures: government policy recommendations, provider and corporate policy recommendations, technical recommendations, research and standardisation recommendations.

    “This paper is aimed at corporate and political decision-makers as well as Social Network application-providers. It also seeks to raise awareness among political and corporate decision-makers of the legal and social implications of new developments in Social Networking technologies. In particular, the findings should have important implications for education and data protection policy.”

--- NOTE: my original HP blog can be found here ---

Monday, October 1, 2007

Lots of Warnings about “Enterprise Web 2.0” Risks – What about Identity 2.0?

A recent article by Robert Mullins, called “Enterprises warned to approach Web 2.0 with caution”, says:

“Danny Allan of IBM had just finished his primer on potential security risks of Web 2.0 applications when enterprise software developers filing out were overheard telling each other, “That was scary!” and “Now I’m depressed.” Allan says he didn’t mean to scare, but to educate. “The lesson is not to run away but to prepare,” said Allan, director of security research at Watchfire, an IBM-owned security firm”

This is also consistent with what HP SPIDynamics said sometimes ago, in particular about security risks and issues with Enterprise Web 2.0 (see here and here).

In a previous post of mine, called “Web 2.0/Ajax “Submission Throttling” and Privacy Concerns” I also highlighted a (simple) example of a potential Web 2.0 privacy threat (ok, this was primarily from a B2C perspective, but this could also apply to enterprise and federated IdM contexts …). I am sure this is just the tip of the iceberg …

I would be interested in knowing what the outcome of a similar risk/security/threat analysis/assessment would *specifically* be for “Identity 2.0”-based solutions (including Liberty Alliance, of course …) – in B2C, Enterprise and federated IdM contexts.

I believe there will be interesting findings, from a privacy and data security perspective, in particular when dealing with personal and confidential information.

--- NOTE: my original HP blog can be found here ---

Thursday, September 27, 2007

Research Report: Lack of Strong Identity and Access Management in UK Businesses …

A recent article by Miya Knights, called “Strong ID and Access Management eludes UK Business” provides an overview of the findings of a recent research report by Insight Consulting, on UK business attitudes towards identity and access management. Here are a few key points highlighted in this article:

“New research into attitudes towards identity and access management has found very few are taking effective steps to address potential security lapses.

Although most UK businesses realise the increased threat from inadequate security systems and policies the research, produced for Siemens-owned Insight Consulting, found 71 per cent of companies still rely solely username and password authentication, which has been criticised for its effectiveness in protecting against malicious attacks.A further 62 per cent of the 259 IT services and management professionals surveyed admitted that their organisation had no information security management system in place, or at least they didn't know if it did.

And more than 90 per cent do not have a fully automated solution capable of producing audit reports detailing network, application and data access, despite the fact that 51 per cent of businesses surveyed now have to deal with increasing partner, supplier and customer system access.

In addition, only 50 per cent of respondents were confident that network access rights of staff members who leave a company are removed or deactivated when they leave - the other half leave outdated user accesses active and open to malicious misuse as well.

Only 22 per cent of businesses have an enterprise single sign-on identity and access management systems in place, which Insight said delivers the fastest return on investment.”

--- NOTE: my original HP blog can be found here ---