NEWS Almost half of all applications have security flaws that are both serious and easily exploitable. According to the latest research from security experts @stake, all of the flaws it discovered were easily preventable if software companies employed reasonably secure development processes. Avi Corfas, executive VP for EMEA @stake, said: "All applications have flaws in them. However, what we looked for were flaws that were not only potentially very damaging, but also easily exploitable by hackers. He told silicon.com: "We found that 47 per cent of applications had this worrying combination of properties." Corfas would not be drawn on what companies software @stake had studied to reach the findings but said the levels of security from different vendors varied enormously. Some applications in the study had 80 per cent less risk of being compromised than others. Corfas said the problems are simple to solve if addressed at the design stage. "Seventy per cent of the flaws came from the design of the applications, rather than the deployment. It is so much cheaper to fix security problems during design than implementation," he said. @stake identified a number of common mistakes by application developers. Firstly, insufficient attention is paid to secure methods of authenticating users. In addition, multi-tiered programs are designed to implicitly trust information passed from tier to tier, giving hackers an easy ride. Corfas called on the application development houses to do more. He said: "Many companies still don't seem to have realised the implications of opening their programs up to the internet. With applications designed to let people like customers and partners in, the boundaries become more diffuse and internal security that much more important."
Security experts blame developers for holes
Clean it up at the source...
Post your comment
In order to post a comment you need to be registered and logged in.
You can also log in with Facebook. Log in or create your silicon.com account below
Get silicon.com's daily newsletter
-

Enter your email to register
Featured white papers
-
Deliver easy email search, storage and retrieval systems
Are you storing up trouble? There is a better way to manage corporate email storage, especially to: - Avoid...
-
Systems engineering: Best practice for development success
Systems engineering isn't just a technical activity in the product lifecycle—it determines the commercial viability of...
-
Securing the rise of the mobile apps market: Code signing and mobile application development
The emergence of mobile applications has fundamentally changed the way that millions of people around the world, play...
Keep in touch with silicon.com
-
Connect with silicon.com on Facebook
Discuss the news of the day with the silicon.com team
-
Follow silicon.com on Twitter
Get regular updates from the silicon.com editors
-
Join the silicon.com LinkedIn networking group
Network with your peers and share expertise
Latest jobs
-
Project Manager
Black Rock Studio [A division of Disney Interactive Media Group] is currently recruiting for a Project Manager to...
-
1st line Support- Croydon
My client- A large consultancy based in Croydon are looking for a 1st/2nd line helpdesk support candidate on an...
-
IT Security Specialist , Big Learning + Move into Pre-Sales
IT Security Specialist , Big Learning + Move into Pre-SalesSC Cleared, UK National - Intensive training offered on...
silicon.com newsletters
-
Stay up to date with silicon.com newsletters
Keep up with the latest news and analysis from silicon.com with our free email newsletters




