ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Businesses warned over Web 2.0 security

Tom Espiner ZDNet.co.uk

Published: 26 Mar 2007 16:37 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security vendor Clearswift has advised companies to review or implement security policies and procedures around Web 2.0 applications after a survey found that 42 percent of company employees aged 18 to 29 had discussed work-related issues on social media websites.

The survey, which was commissioned by Clearswift and conducted by YouGov, polled more than 1,000 business employees. Clearswift said that the results of the survey illustrate how widely-used Web 2.0 social communication has become, and that this signalled a risk of leakage of confidential company information.

Some marketers have attempted to harness social-networking sites such as YouTube for their campaigns, while many corporates are keen to use wikis, RSS and content tagging because of clear user benefits.

However, 59 percent of office workers in the 18 to 29 age bracket believe they should be entitled to use Web 2.0 content from their work computer for personal reasons.

"The younger generation have never known a business world without the internet. Young office workers come out of university having used social-networking sites. They see nothing unacceptable using corporate resources for personal use," said Ian Bowles, chief operations officer for Clearswift. "Content is king. If you have policies around content, you can control what's going on, and prevent partial disclosure of financial results, or product design leaks."

As well as risks to company intellectual property, Clearswift highlighted risks that arise from using Web 2.0 technologies themselves. According to Clearswift's ThreatLab manager, Pete Simpson, Ajax and XML code used to develop web applications mean those applications can potentially be subverted. "To secure a website is not trivial," said Simpson. "For a determined and skilled attacker, there are many ways to inject malicious code into a network. You can inject JavaScript code into a web page using cross-site scripting, for example."

Cross-site scripting (XSS) involves injecting malicious code into pages served by other domains. An attacker can gain access privileges to sensitive page content and session cookies by exploiting XSS vulnerabilities.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
3 out of 6 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

GBS-0088233 CRM Infrastructure Architect

Your responsibilities will include: - Working with IBM Strategy Consultants and Application Architects and our clients to explore optimal platforms ...

HR Project Manager - City - 6 month contract

Please send your CV in for immediate feedback and call Andy Simpson on 0207 469 8999 for further information. Ideally, you will have previous ...

Lead Statistician and Survey Designer

A leader in market research has a new job for a lead statistician and survey builder to join them at company HQ in Oxfordshire. As lead statistician ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation