<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sensitive Data Exposure   #3 on the 2017 OWASP Application Security Risks in Career Discussions</title>
    <link>https://community.isc2.org/t5/Career-Discussions/Sensitive-Data-Exposure-3-on-the-2017-OWASP-Application-Security/m-p/3895#M319</link>
    <description>&lt;P&gt;"Many web applications and APIs do not properly protect sensitive data, such as financial,&lt;BR /&gt;healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit&lt;BR /&gt;card fraud, identity theft, or other crimes. Sensitive data may be compromised without extra&lt;BR /&gt;protection, such as encryption at rest or in transit, and requires special precautions when&lt;BR /&gt;exchanged with the browser."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So saith OWASP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is not just GDPR (which is a significant compliance issue), but a much larger problem associated with a general malaise in the industry.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We worry more about patching the latest patch than thinking and preventing the issue.&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No wonder the issue came from nowhere (OWASP 2013 to #3 OWASP 2017)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How about not exposing the data just because it is "easier to keep all the data in one file" (ie data structure).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are hundreds of "How about?"'s, but if we restructure our thinking on the issue as a whole there are better solutions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I predict that it (Sensitive Data Exposure) will be #1 or #2 next year on the OWASP Top 10, and I predict the cost in 2018 will approach $1 billion to resolve breaches, compensate the afflicted, and patch.&amp;nbsp;&amp;nbsp; I predict that at least 1, but possibly 2 very highly compensated CISO's and even other CxO's will lose their position in 2018.&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We need solutions, not palliatives (go ahead look it up).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What say you?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 26 Nov 2017 16:45:22 GMT</pubDate>
    <dc:creator>vistauxx</dc:creator>
    <dc:date>2017-11-26T16:45:22Z</dc:date>
    <item>
      <title>Sensitive Data Exposure   #3 on the 2017 OWASP Application Security Risks</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Sensitive-Data-Exposure-3-on-the-2017-OWASP-Application-Security/m-p/3895#M319</link>
      <description>&lt;P&gt;"Many web applications and APIs do not properly protect sensitive data, such as financial,&lt;BR /&gt;healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit&lt;BR /&gt;card fraud, identity theft, or other crimes. Sensitive data may be compromised without extra&lt;BR /&gt;protection, such as encryption at rest or in transit, and requires special precautions when&lt;BR /&gt;exchanged with the browser."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So saith OWASP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is not just GDPR (which is a significant compliance issue), but a much larger problem associated with a general malaise in the industry.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We worry more about patching the latest patch than thinking and preventing the issue.&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No wonder the issue came from nowhere (OWASP 2013 to #3 OWASP 2017)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How about not exposing the data just because it is "easier to keep all the data in one file" (ie data structure).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are hundreds of "How about?"'s, but if we restructure our thinking on the issue as a whole there are better solutions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I predict that it (Sensitive Data Exposure) will be #1 or #2 next year on the OWASP Top 10, and I predict the cost in 2018 will approach $1 billion to resolve breaches, compensate the afflicted, and patch.&amp;nbsp;&amp;nbsp; I predict that at least 1, but possibly 2 very highly compensated CISO's and even other CxO's will lose their position in 2018.&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We need solutions, not palliatives (go ahead look it up).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What say you?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Nov 2017 16:45:22 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Sensitive-Data-Exposure-3-on-the-2017-OWASP-Application-Security/m-p/3895#M319</guid>
      <dc:creator>vistauxx</dc:creator>
      <dc:date>2017-11-26T16:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: Sensitive Data Exposure   #3 on the 2017 OWASP Application Security Risks</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Sensitive-Data-Exposure-3-on-the-2017-OWASP-Application-Security/m-p/3899#M321</link>
      <description>&lt;P&gt;"&lt;EM&gt;N&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;ot exposing the data&lt;/EM&gt;" is difficult, because it was probably gathered for a valid reason, and nowadays customers expect to be able to interact with it through the same UI.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Online shopping? "&lt;EM&gt;Please phone us if you want to confirm or change your card or address details&lt;/EM&gt;" is another way of saying "&lt;EM&gt;We want to lose market share&lt;/EM&gt;". Exceptions and complaints? "&lt;EM&gt;Please fill in form 37/b and post it to our head office...&lt;/EM&gt;"&amp;nbsp; is very 1980s, but not viable today. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Easy&amp;nbsp;solutions are scarce, alas.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Nov 2017 17:03:36 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Sensitive-Data-Exposure-3-on-the-2017-OWASP-Application-Security/m-p/3899#M321</guid>
      <dc:creator>bobrayner</dc:creator>
      <dc:date>2017-11-26T17:03:36Z</dc:date>
    </item>
  </channel>
</rss>

