EU cybersecurity body urges Web security review

 

Summary

update The European Network and Information Security Agency says existing standards governing Web and browser technologies reaching "point of no return"; proposes improvements to 13 upcoming specifications.

Events

Echelon 2012
June 11 and 12, 2012

University Cultural Centre, National University of Singapore

Startup Asia Jakarta 2012
June 7 and 8, 2012

12th Floor, Annex Building, Wisma Nusantara Complex, Jl. M.H. Thamrin No. 59 Jakarta 10350, Indonesia

MMA Forum Singapore
April 23-25, 2012

Grand Hyatt Singapore

update Existing Web standards that determine Web and browser technologies are "reaching point of no return", said the European Network and Information Security Agency (Enisa). To strengthen security-in-design of upcoming next-generation Web technologies, it is proposing improvements to 13 specifications, including HTML5.

The European Union's cybersecurity watchdog published a paper last Sunday recommending the review and improvement of 13 World Wide Web Consortium (W3C) specifications covering HTML5, cross-origin communication interfaces, device application programming interfaces (APIs) and widgets.

Elaborating, Enisa said the Web browser is "arguably the most security-critical component in our information infrastructure" as it has become the channel through which most of the world's information passes.

"Banking, social networking, shopping, navigation, card payments, managing high value cloud services and even critical infrastructures such as power networks--almost any activity you can imagine now takes place within a browser window," it stated.

This, in turn, has made browsers an increasingly "juicy target" for cybercriminals, Enisa noted. To back up its observation, the paper pointed out that the volume of Web-based attacks per day increased by 93 percent in 2010 compared with the year before.

However, many of the existing standards governing Web and browser technologies are "reaching a point of no return" and if there is no review and improvement in the 13 specifications identified, the opportunities for "security-by-design will be lost". This is because once the current suite of new standards reach recommendation status within W3C in 2014, it will be "non-negotiable for several years to come", the agency stated, pointing out that the current iteration of HTML has been unchanged since 1999.

Enisa's recommendations focus on controls functionality, permission system design, end-user policing and more detailed user interface requirements, among others.

The W3C has welcomed Enisa's recommendations, according to a Monday report by technology news site ComputerWeekly.com. "We have encouraged Enisa to report the issues it has identified to the relevant W3C Working Groups," said Thomas Roessler, W3C's security lead.

Security vendor Symantec also received Enisa's proposals positively. Ng Kai Koon, senior manager of legal and public affairs at Symantec Singapore, noted that with the increasingly treacherous and rapidly evolving threat landscape, the company "welcomes any initiatives by government agencies that help improve [the overall] cybersecurity posture".

"We believe that cultivating a strong public-private partnership plays an important role in enhancing security awareness, and are committed to sharing insights and best practices to help develop national capabilities for governments to defend essential and critical infrastructure from internal and external threats," Ng added.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

ZDNet Asia Live

Rise in <b>Chinese</b>-funded acquisitions could trigger more hurdles http://t.co/0pXBS1HR

Rise in Chinese-funded acquisitions could trigger more hurdles: By Ellyne Phneah , ZDNet Asia on May 22, 2012 (6... http://t.co/W3SOdw2c

RT @zdnetasia: CFOs increasingly involved in IT investment decisions. http://t.co/8QrfwOSb

CFOs increasingly involved in IT investment decisions http://t.co/XD1LerFq via @zdnetasia #PrivateCloud #SC2012 #CAPEX

Rise in Chinese-funded acquisitions could trigger more hurdles. http://t.co/VC3G3m3o

RT @zdnetasia: Rise in Chinese-funded acquisitions could trigger more hurdles. http://t.co/VC3G3m3o

So much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...

47 minutes ago by y15822137359 on 5 SaaS adoption speed bumps to avoid

Rise in Chinese-funded acquisitions could trigger more hurdles - ZDNet Asia: Rise in Chinese-funded acquisitions... http://t.co/bZaAQnRL

Rise in Chinese-funded acquisitions could trigger more hurdles http://t.co/mIsuZjnU http://t.co/erFX4aVv #arcavir

http://t.co/VNaZtseV Rise in Chinese-funded acquisitions could trigger more hurdles: "Cash r... http://t.co/N0gZZEdR http://t.co/wiqY9ktt

Rise in Chinese-funded acquisitions could trigger more regulatory clearance issues overseas http://t.co/cvLSpTwo #in

Alibaba seeks $2.3B from shareholders for Yahoo deal. http://t.co/qLRAhRQk

CFOs increasingly involved in IT investment decisions. http://t.co/8QrfwOSb

Quickflix WatchNow 2.0 http://t.co/XWti5VWT

Official UEFA #EURO2012 app with Orange 2.0 http://t.co/yoAOXTI1 #hotpeopleifollow

Why wouldn't they be?: CFOs increasingly involved in IT investment decisions http://t.co/4gHYrmQy via @zdnetasia

I reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...

1 day ago by wykoong on Gartner: Mobile CRM gives better ROI than social

This video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...

1 day ago by TradeBrother on A quick fill handle trick for Microsoft Excel

waiting...

3 days ago by eapete on What should count in a company's market value?

Boy, you've opened a can of worms now.

Wait for the rants & raves.

3 days ago by eapete on What should count in a company's market value?

I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...

4 days ago by wykoong on Drop the egos, copy ideas, then innovate