How To

How to Secure Web Services

The next new (vulnerable) thing

By Simson Garfinkel

Page 4

Of course, you can deploy completely useful Web services using only basic user name and password authentication, no encryptionand never have a single security problem. But if you are that reckless, be sure to keep it a secret.Finally, a PleaWhen a spate of mass-mailing computer worms and viruses hit this past August, my e-mail inbox was flooded. But my inbox wasn't filled with copies of a virus; it was filled with e-mail messages from antivirus systems all over the world telling me that I had sent them a virus, and that the message had been filtered.

My computer was never infected with a virus. Other people's computers were infected, but they were sending e-mail messages with faked "from" addresses. Years ago it made sense to send e-mail to people who were sending out virus-infected e-mail messages. But those days have long passed. Today the vast majority of worms and viruses fake the return address. Antivirus systems that send out notification e-mail messages merely compound the problem.

On one day I received more than 200 of these notification messagesmessages that were supposed to be helpful. And I was one of the lucky ones; someone I know from the MIT Media Lab received more than 2,300 messages in one 24-hour period. If your company's antivirus system is set up to send these notification messages, please change the configuration. Otherwise, your antivirus system is just making the problem worse.

Other stories by Simson Garfinkel

$firstKeyword

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Security Directions: A Virtual Conference

Security Directions Available On Demand Sept. 30 - Dec. 30

Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.

» Register Now

WEBCAST
Protecting PII: How to Work with IT to Manage Risk

Compuware Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.

» View this Webcast

Featured Sponsors