You are here: silicon.com > Software > Security Strategy

Security Strategy

Web 2.0 security warning for business

Mind the leaks...

Tags: web 2.0, leak

By Tom Espiner

Published: 27 March 2007 08:45 GMT

Security vendor Clearswift has advised companies to review or implement security policies and procedures around web 2.0 applications after a survey found that 42 per cent of company employees aged 18 to 29 had discussed work-related issues on social media websites.

The survey, which was commissioned by Clearswift and conducted by YouGov, polled more than 1,000 business employees. Clearswift said the results of the survey illustrate how widely used web 2.0 social communication has become, and that this signalled a risk of leakage of confidential company information.

Some marketers have attempted to harness social-networking sites such as YouTube for their campaigns, while many corporates are keen to use wikis, RSS and content tagging because of clear user benefits.

However, 59 per cent of office workers in the 18 to 29 age bracket believe they should be entitled to use web 2.0 content from their work computer for personal reasons.

Ian Bowles, chief operations officer for Clearswift, said: "The younger generation have never known a business world without the internet. Young office workers come out of university having used social-networking sites. They see nothing unacceptable using corporate resources for personal use. Content is king. If you have policies around content, you can control what's going on, and prevent partial disclosure of financial results, or product design leaks."

As well as risks to company intellectual property, Clearswift highlighted risks that arise from using web 2.0 technologies themselves. According to Clearswift's ThreatLab manager, Pete Simpson, Ajax and XML code used to develop web applications mean those applications can potentially be subverted. "To secure a website is not trivial," said Simpson. "For a determined and skilled attacker, there are many ways to inject malicious code into a network. You can inject JavaScript code into a web page using cross-site scripting, for example."

Cross-site scripting (XSS) involves injecting malicious code into pages served by other domains. An attacker can gain access privileges to sensitive page content and session cookies by exploiting XSS vulnerabilities.

Tom Espiner writes for ZDNet UK

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead

Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy


  • Jobs
Digital Project Manager

Document achievements, highlight risks and issues. On behalf of my client, a digital agency based in Central London, i am looking for a Client facing ...

Online Programmer/ 25k/ basic Javascript/ Flash/ HTML/ 2:2 above/ Reading/ urgent

A leading market research software consultancy is seeking an online survey creator who will create online surveys using specialist market research ...

Senior Web Developer - 3.5, ASP.NET, Social Networking - London

Senior .NET Developer - 3.5, ASP.NET, Social Networking - London Senior ASP.net, C# developer urgently required to join the media arm of an expanding ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: