<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Sonatype Blog &#187; #OSSsecurity</title>
	<atom:link href="http://blog.sonatype.com/people/tag/osssecurity/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.sonatype.com/people</link>
	<description>Sonatype is transforming software development with tools, information and services that enable organizations to build better software, faster, using open-source components.</description>
	<lastBuildDate>Thu, 16 May 2013 18:53:09 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>We&#8217;re a Java shop, we&#8217;re not going to get hacked&#8230;</title>
		<link>http://blog.sonatype.com/people/2012/03/were-a-java-shop-were-not-going-to-get-hacked/</link>
		<comments>http://blog.sonatype.com/people/2012/03/were-a-java-shop-were-not-going-to-get-hacked/#comments</comments>
		<pubDate>Tue, 27 Mar 2012 13:55:24 +0000</pubDate>
		<dc:creator>Tim O'Brien</dc:creator>
				<category><![CDATA[Nexus]]></category>
		<category><![CDATA[#OSSsecurity]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.sonatype.com/people/?p=10544</guid>
		<description><![CDATA[This article is another in a series of articles associated with our Executive Brief. To access the executive brief, “Addressing Security Concerns in Open-Source Components,” visit www.sonatype.com/securitybrief. You can follow the conversation on Twitter using the hashtag #OSSsecurity. I just wanted to reiterate the key point of yesterday&#8217;s security brief which is: &#8220;You and everyone [...]]]></description>
				<content:encoded><![CDATA[<p><em>This article is another in a series of articles associated with our Executive Brief. To access the executive brief, “Addressing Security Concerns in Open-Source Components,” visit <a href="http://www.sonatype.com/securitybrief">www.sonatype.com/securitybrief</a>. You can follow the conversation on Twitter using the hashtag #OSSsecurity.</em></p>

<p>I just wanted to reiterate the key point of yesterday&#8217;s security brief which is: <strong>&#8220;You and everyone else in the world are likely downloading vulnerable components.&#8221;</strong> If you don&#8217;t believe me, then take a look at this graph:</p>

<p><a href="http://www.sonatype.com/people/wp-content/uploads/2012/03/LogScaleVuln.png"><img class="aligncenter size-full wp-image-10545" title="LogScaleVuln" src="http://www.sonatype.com/people/wp-content/uploads/2012/03/LogScaleVuln.png" alt="" width="650" /></a></p>

<p>First, note the logarithmic scale &#8211; downloads over an entire year.   Then, take a look at the left-side of the chart. See anything familiar?     GWT, Spring, Struts, CXF, Xerces?   If you use these components, you should try to identify which versions are affected by widely known CVE vulnerabilities.   It&#8217;s that simple, if you use these components it would be a good idea to browse the CVE database, or to <a href="http://www.sonatype.com/nexus/">take a look at Nexus Professional&#8217;s Repository Health Check</a>.</p>

<h2>Really, attackers aren&#8217;t going to go to the trouble&#8230;</h2>

<p>Developers, you might be thinking, &#8220;an insecurity in GWT or Xerces, who&#8217;s going to trouble of doing that much research?   Who&#8217;s <em>really</em> going to hack into Megabank via some obscure AJP vulnerability in a Tomcat connector?&#8221;   And if you are asking these questions as a way to shuffle this all under the rug, I understand.  There&#8217;s enough work in the pipeline already and you don&#8217;t need another thing to worry about.   As developers we&#8217;re not going to turn into security professionals overnight, but we can start <a href="http://www.sonatype.com/nexus">using tools like Nexus Professional</a> to help identify vulnerable components and isolate us from deploying known security problems to production.</p>

<p>It isn&#8217;t the likelihood that someone will hack GWT that is the issue, it is the idea that deploying any code with a known security vulnerability needs to be identified as a disqualifier.    The idea that if you get compromised and someone realizes that it was a known vulnerability (for years): developers need to be motivated to avoid this embarrasing situation.   The point I&#8217;ve tried to make on this blog is that we (developers) are not really paying attention to this problem because we just assume that it is someone else&#8217;s problem.</p>

<h2>Ignoring Security: It isn&#8217;t a question of <strong>if</strong> you&#8217;ll get hacked, it&#8217;s <strong>when</strong></h2>

<p>The issue of data and systems security has repeatedly been front-page news time and time again over the past year.   Groups like Anonymous and Lulzsec made a public sport in 2011 of hacking into serious organizations and making every effort to embarrass and ridicule them for lax security.  The last few years have been pretty embarrassing years for a lot of security departments at large corporations and a few governments.   2012 promises to be even more active with McAfee predicting <a href="http://venturebeat.com/2011/12/28/mcafee-2012-security-predictions/">the reorganization of Anonymous</a>, but focusing on these high-profile, news-generating events ignores the scope of the problem.  It isn&#8217;t about volume, it is about your exposure to this risk.</p>

<p>I&#8217;ve seen some recent attacks in action.   Attacks on both Java-based web architectures and PHP-based architectures.   While it&#8217;s true that PHP-based applications present a much larger and more insecure surface area to attack, it has to be said that Java-based web applications and .NET present a much more lucrative target.   An attacker can compromise all the two-bit Drupal instances in the world without stumbling upon anything worth intruding, or they can focus on a multi-month strategy of social engineering and direct attacks to compromise one the Global 100 financial institutions that are downloading insecure dependencies every day.</p>

<h2>Welcome to the Security Theater</h2>

<p>If you are banking on the fact that attacking Struts 2 or Log4J is just too esoteric for most hackers to do, you are participating in something Bruce Schneier calls Security Theater, and that&#8217;s really what I&#8217;m taking away from this study.   Some of these institutions are so invested in presenting an image of trust and security that they will spend millions on Super Bowl ads and marketing efforts to purchase customer trust.  But, at the end of that day they continue to download vulnerabilities.  It doesn&#8217;t match up, we need a change of culture in development and security needs to be top of mind.</p>

<p>It&#8217;s time for developers to start taking security seriously.    You could choose to be proactive about the problem and use tools like <a href="http://www.sonatype.com/nexus">Nexus Professional</a> to automatically correlate CVE vulnerabilities from CERT with your artifacts, or you can wait until someone replaces your company website with a funny picture and lose the ability to download artifacts from Central altogether.   The choice is yours.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2012/03/were-a-java-shop-were-not-going-to-get-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Today&#8217;s Security Brief: Application security is widely neglected (by some surprising companies)</title>
		<link>http://blog.sonatype.com/people/2012/03/todays-security-brief-application-security-is-widely-neglected-by-some-surprising-companies/</link>
		<comments>http://blog.sonatype.com/people/2012/03/todays-security-brief-application-security-is-widely-neglected-by-some-surprising-companies/#comments</comments>
		<pubDate>Mon, 26 Mar 2012 15:53:51 +0000</pubDate>
		<dc:creator>Tim O'Brien</dc:creator>
				<category><![CDATA[Nexus]]></category>
		<category><![CDATA[Sonatype]]></category>
		<category><![CDATA[#OSSsecurity]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[The Central Repository]]></category>

		<guid isPermaLink="false">http://www.sonatype.com/people/?p=10529</guid>
		<description><![CDATA[Today we published a paper with Aspect Security, and it&#8217;s a shocking look at how few people are paying attention to application security. If you consume dependencies from the Central Repository and you don&#8217;t want to get hacked, I&#8217;d suggest reading the report and understanding some of the challenges, I&#8217;d also check out some of [...]]]></description>
				<content:encoded><![CDATA[<p>Today we <a href="http://ctt.marketwire.com/?release=866321&amp;id=1407793&amp;type=1&amp;url=http%3a%2f%2fwww.sonatype.com%2fsecuritybrief">published a paper with Aspect Security</a>, and it&#8217;s a shocking look at how few people are paying attention to application security.  If you consume dependencies from the Central Repository and you don&#8217;t want to get hacked, I&#8217;d suggest <a href="http://www.sonatype.com/securitybrief">reading the report</a> and understanding some of the challenges, I&#8217;d also check out some of these statistics.  Here are three that jumped out at me:</p>

<ul>
    <li>Global 500 organizations downloaded more than 2.8 million insecure components in one year.</li>
    <li><strong>Financial services firms are the most exposed</strong>: Global 100 financial services firms alone downloaded more than 567,000 insecure components in one year.</li>
    <li>48% (a little under half) of organizations don&#8217;t have an inventory of Open source software used in production.  (If there&#8217;s a new vulnerability discovered in something like GWT, who knows if we have that in production.)</li>
</ul>

<p>To access the executive brief, &#8220;Addressing Security Concerns in Open-Source Components,&#8221; visit <a href="http://www.sonatype.com/securitybrief">www.sonatype.com/securitybrief</a>. You can follow the conversation on Twitter using the hashtag #OSSsecurity.</p>

<p><strong>NOTE:</strong> Now, Developers, I know what you are thinking, you see the word &#8220;Executive Brief&#8221; and immediately dismiss this as C-level corporate-speak.  Sure, there&#8217;s a little bit of that, but you&#8217;ll also learn how to own any unpatched Struts 2 application with a known vulnerability.    <strong>If you use Struts, maybe <a href="http://www.sonatype.com/securitybrief">you should read this report</a> before your boss uncovers a vulnerability in your application?</strong></p>

<p><a href="http://www.sonatype.com/people/wp-content/uploads/2012/03/Inventory.png"><img class="aligncenter size-full wp-image-10533" title="Inventory" src="http://www.sonatype.com/people/wp-content/uploads/2012/03/Inventory.png" alt="" width="665" height="388" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2012/03/todays-security-brief-application-security-is-widely-neglected-by-some-surprising-companies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
