Businesses warned over Web 2.0 security

By Tom Espiner, ZDNet UK
Tuesday, March 27, 2007 11:02 AM

Security vendor Clearswift has advised companies to review or implement security policies and procedures around Web 2.0 applications after a survey found that 42 percent of U.K. company employees aged 18 to 29 had discussed work-related issues on social media Web sites.

The survey, which was commissioned by Clearswift and conducted by YouGov, polled more than 1,000 business employees. Clearswift said that the results of the survey illustrate how widely-used Web 2.0 social communication has become, and that this signaled a risk of leakage of confidential company information.

Some marketers have attempted to harness social-networking sites such as YouTube for their campaigns, while many corporates are keen to use wikis, RSS and content tagging because of clear user benefits.

However, 59 percent of office workers in the 18 to 29 age bracket believe they should be entitled to use Web 2.0 content from their work computer for personal reasons.

"The younger generation have never known a business world without the Internet. Young office workers come out of university having used social-networking sites. They see nothing unacceptable using corporate resources for personal use," said Ian Bowles, chief operations officer for Clearswift. "Content is king. If you have policies around content, you can control what's going on, and prevent partial disclosure of financial results, or product design leaks."

As well as risks to company intellectual property, Clearswift highlighted risks that arise from using Web 2.0 technologies themselves. According to Clearswift's ThreatLab manager, Pete Simpson, Ajax and XML code used to develop Web applications mean those applications can potentially be subverted. "To secure a Web site is not trivial," said Simpson. "For a determined and skilled attacker, there are many ways to inject malicious code into a network. You can inject JavaScript code into a web page using cross-site scripting, for example."

Cross-site scripting (XSS) involves injecting malicious code into pages served by other domains. An attacker can gain access privileges to sensitive page content and session cookies by exploiting XSS vulnerabilities.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Cost and graphics concerns delay a VDI project

Tech Management

Virtual desktops are a serious paradigm shift and Scott Lowe is taking it in a slow and measured way. In this article, he provides an update on ongoing VDI efforts at Westminster College.


Read more »



Do we need more delivery centers?

Blog thumbnail

As I wrote a while back in about "racing to subsidies", there certainly is an increased focus by governments to attract delivery centers to their region. To do that, many..... by Michael Rehkopf

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web