R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Security expert warns of web services threat

Companies must do more to protect web systems or business will suffer

Phil Muncaster, IT Week 23 May 2006
ADVERTISEMENT

Web services will flounder unless the web is made more secure, a leading security expert has warned.

Ahead of his keynote speech at the World Wide Web conference in Edinburgh this week, Phillip Hallam-Baker, principal scientist at security specialist VeriSign, told IT Week that internet crime is the biggest challenge facing the web community now that criminals are selling stolen credentials, custom-written viruses and other illegal services online.

"I've spent a lot of time on web services and if security is not built into them they'll be dead on arrival," Hallam-Baker warned. "If you don't secure the systems people are already using, corporations won't expose their entire supply chain [by using web services across organisational boundaries] in an environment rife with crime."

To encourage consumer and corporate trust in the internet, Hallam-Baker called for more effort to boost the web's authentication and accountability infrastructure, starting with stronger SSL Certificates allowing certification authority and merchant logos to be displayed in the browser bar.

"Eventually we will have to have branded [communications] where every message [including] emails, instant messages and VoIP [traffic] has to be consistently authenticated and branded," Hallam-Baker said. "The web experience needs to have as consistent a logo as the real world."

Hallam-Baker also called for greater efforts to identify and prevent networks of compromised computers, known as bot-nets, from being used in denial-of-service and other attacks, to stop the spread of malware infections, "from a public health point of view".

"I think we're going to win [the battle to secure the internet]," he said. " But if we don't fix it soon future uses [of the web] will be put on hold. We need to bring down net crime in the old web before we convince people [to invest in new web technologies]."

See also:

W3C promises improved addressing for web services messages  10 May 2006

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Reading, Berkshire, United Kingdom | EDS
Position # 397874 IP Network Administrator Location - Reading Job Description: There is a requirement for an IP network administrator to join the Infrastructure Services operational support team to manage the movement of network resources, ... more >
London, United Kingdom | The Moving Picture Company
Web Developer - London   MPC's continued success is dependent on a continued investment in technology so that its clients continue to enjoy the highest possible quality of work and service. Key to MPC's offering is ... more >
London, United Kingdom | City of London
ICT Project Officer - Guildhall, London EC2 18-month fixed-term contract Bring your project management expertise to one of the country's most prestigious institutions. The City of London is the local authority for the Square Mile, ... more >
Reading, Berkshire, United Kingdom | EDS
Position - EA Integrator Location - Reading Job Description: A skilled System Integrator to integrate application Test Harnesses to support business requirements. The Candidate will possess specific experience of enterprise systems, component validation and integrating ... more >
More job opportunities