Berners-Lee: Web security a 'never-ending battle'

By Tom Espiner, ZDNet UK
Monday, September 24, 2007 08:16 AM

The man credited with invention of the world wide Web, Sir Tim Berners-Lee, has warned that Web security is a "never-ending battle".

Speaking at a lecture hosted by the Institution of Engineering and Technology in London on Thursday, Berners-Lee said that, while he was against Web censorship per se, both technological and educational means should be employed to tackle Internet security issues.

"A lot of security work is going on [on the Web], but security is a never-ending battle," said Berners-Lee. "The Web is used by humanity, and humanity has a dark and a light side. I'm an optimist--I think the light side wins. The Web is supposed to be a blank sheet of paper, and you can write dark things on that paper as well as light. If you tried to control the Web, you would end up with engineers deciding what the truth is, which is worse. But, if we see nasty things happening, we should try and tweak [the Web]. If you look at any protocol anywhere, there are technical and social restrictions."

Berners-Lee said that Web technology had been originally designed for "a friendly academic environment". Numerous technologies including e-mail and wikis had been conceived in a positive light, and are being used to the good by large numbers of people. But he said that the negative side of technology use should be addressed.

"We made the e-mail system, and in turn it's used by a huge number of people. The person who designed wikis led to Wikipedia [being founded]. E-mail and the Web allow the mass sending of information, but were designed for a friendly academic environment. You have to look at the result: there are huge volumes of spam, phishing attacks--that's bad, and we have to fix that--that is the cycle of Web sites," said Berners-Lee.

Phishing attacks have the potential to damage consumer confidence in the Web, because consumers are "now not sure if it's [their] bank". Berners-Lee called for a mixture of technological and educational measures to mitigate Web-security issues. Technical means should be employed to mitigate current Web 2.0 threats, such as cross-site scripting attacks, he said, while good security practice should be encouraged among end users.

Cross-site scripting attacks exploit JavaScript flaws to inject malicious code into a Web page during a user's browser session. "Cross-site scripting attacks are a huge problem," said Berners-Lee. "Other times it's just straightforward education. Don't train users to type their passwords into Web sites in the clear. Banks are training [U.S. users] to give their social security number. There are some security flaws they haven't thought they're training people to do."


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Save changes to all open Word documents at one time

Microsoft Office Suite

If your Word sessions often wind up with a lot of open documents, this obscure command can streamline the process of closing them and saving your changes.


Read more »



Do we need more delivery centers?

Blog thumbnail

As I wrote a while back in about "racing to subsidies", there certainly is an increased focus by governments to attract delivery centers to their region. To do that, many..... by Michael Rehkopf

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web