All talks

LASCON 2022 · 2022/10

No Code Risk: What Happens When We Leave No Code up for Grabs

Loading presentation…

Read the transcript

Transcript

AI generated from recording.

Introduction and Agenda

00:54 Presenter: Thank you everyone for coming. My name is Michael. We’re going to talk about the

00:58 Presenter: about low-code, no-code.

01:00 Presenter: The one thing I’m going to guarantee

01:02 Presenter: about this talk is that it’s going to be different

01:04 Presenter: from the ones that you’ve heard in the last

01:06 Presenter: couple of days. I’m not sure if that’s a good

01:08 Presenter: or a bad thing, but you’ll decide.

01:11 Presenter: So

01:13 Presenter: briefly about me,

01:15 Presenter: I’ve been working

01:16 Presenter: around low-code, no-code security for

01:18 Presenter: the last three to four years.

01:20 Presenter: Spent several years at Microsoft

01:22 Presenter: as part of the CTO division

01:24 Presenter: at Azure.

01:27 Presenter: focused on IoT, API security, application security, really all around.

01:32 Presenter: About a year and a half ago, I co-founded Zenity,

01:35 Presenter: which is a company focused on low-code, no-code security.

01:37 Presenter: That’s also where I get the visibility to discuss these things today.

01:41 Presenter: I also lead an OWASP group that is dedicated to security risks for low-code, no-code.

01:47 Presenter: And we’re going to show a lot of that work today.

01:52 Presenter: There’s a bunch of more information out there.

01:55 Presenter: You can see my links in there.

01:57 Presenter: So if you’re interested, reach out.

02:01 Presenter: Here’s what we’re going to do today in this talk.

Defining Low‑Code and No‑Code & Their Enterprise Impact

02:04 Presenter: So the first thing is kind of figuring out what low-code and no-code is,

02:08 Presenter: making sure that we are going to speak the same language.

02:10 Presenter: We’re going to see just how pervasive this is in large organizations.

02:16 Presenter: You’ll see this in a moment, but it’s really surprising

02:18 Presenter: how fast this thing is growing within the enterprise.

02:22 Presenter: We’ll understand how does the SDLC translate to the world of low-code development.

02:27 Presenter: And then we’ll go through the OWASP top 10 and figure out what are the actual risks that we’re seeing in these types of applications.

02:35 Presenter: So the next slide I’m going to show you is probably the most important slide in this entire talk.

02:43 Presenter: This is actually random.

02:45 Presenter: This is anonymous statistics from a single organization, a single Fortune 500 organization.

02:51 Presenter: And you’re seeing the number of applications that they have within the organization that were built with low code.

02:59 Presenter: And these are not exaggerated numbers.

03:02 Presenter: These are actually real numbers from a real customer environment.

03:05 Presenter: And now the amazing thing about this is just the rate of growth.

03:11 Presenter: We’ll talk in a moment about who’s building those types of applications.

03:15 Presenter: This is not only built by IT or professional developers.

03:19 Presenter: This is mostly built by business professionals.

03:22 Presenter: This is also why this graph is so interesting,

03:25 Presenter: and it’s also why this entire subject is important.

03:28 Presenter: It’s because with these kind of numbers,

Why Low‑Code Is Growing Rapidly in the Enterprise

03:31 Presenter: our traditional approaches, manual interventions,

03:34 Presenter: security reviews, those won’t really help.

03:38 Presenter: So we’ll see what we can do.

03:42 Presenter: Let’s try and figure out how did low code get into such high numbers,

03:49 Presenter: We’ll make sure that we are all speaking the same language about what no code is.

03:55 Presenter: This tries to capture the reason behind low code.

03:58 Presenter: We all understand that IT can only do so much,

04:01 Presenter: and the business has multiple different needs.

04:06 Presenter: Of course, this is kind of a perennial problem.

04:09 Presenter: It’s been around for a long time,

04:11 Presenter: and there are many different technologies that are trying to bring

04:14 Presenter: basically more power to the hands of the business users

04:17 Presenter: so they can solve their own problems.

04:19 Presenter: If this sounds familiar, it’s because it is.

04:22 Presenter: So this is low code is just one point in a large trend across multiple years of IT decentralization, giving more power to people that are non-technical.

04:32 Presenter: And the cool thing about this is that, of course, the folks in the business, they are the ones that can impact the business the most.

04:40 Presenter: This is what makes this very important.

04:42 Presenter: In terms of what people are building here.

04:45 Presenter: So there are a whole bunch of stuff.

04:49 Presenter: But people are building like a small automation.

04:51 Presenter: So if something happens in my email or if somebody uploads their file to SharePoint, then do something else.

04:58 Presenter: They plug things together.

04:59 Presenter: They also build business applications that are about facilitating a specific workflow.

05:06 Presenter: And you’ll see examples for that in a moment.

05:08 Presenter: And it’s all kind of drag and drop.

05:10 Presenter: And these platforms have really matured in the last few years, which makes this actually kind of a reality.

Business‑Critical Low‑Code Applications in Practice

05:20 Presenter: It’s growing within the enterprise.

05:22 Presenter: Now, one of the things that drives the accelerated growth of this area

05:31 Presenter: is the fact that these low-code, no-code applications,

05:34 Presenter: you don’t really have to decide as an organization

05:37 Presenter: that you’re going to use them.

05:39 Presenter: You don’t really get the choice.

05:40 Presenter: And here’s the reason why.

05:42 Presenter: All of the vendors that you’re seeing here,

05:44 Presenter: but actually more than that,

05:47 Presenter: every major SaaS vendor has been shifting to become kind of a low-code, no-code platform in the last few years.

05:55 Presenter: And this means that, first of all, this is already out there in most organizations, right?

06:00 Presenter: Because which enterprise is not a Microsoft or a ServiceNow or a Salesforce user?

06:06 Presenter: It’s kind of non-existent.

06:07 Presenter: The second thing is that this also means that these low-code apps, by definition, they work closely to business data.

06:17 Presenter: They operate, they transact with business data, which makes this really important for us to tackle.

06:26 Presenter: Now, this is the kind of value prop behind low-code.

06:30 Presenter: The main idea is reducing the barrier to entry to build your own things, to become kind of a developer.

06:38 Presenter: And you don’t have to worry about all of the little details like authentication and user management.

06:43 Presenter: And you’ll see in a moment that a whole bunch of other things are not really covered.

06:49 Presenter: One of the things that I’m sure you’re thinking and recalling the graph that I showed earlier,

06:56 Presenter: The one important question is kind of what types of apps are these?

07:01 Presenter: How big are they?

07:02 Presenter: How important are they?

07:04 Presenter: So in recent years, we’ve seen low-code applications really become business critical,

07:10 Presenter: or some of them at least, really become business critical.

07:12 Presenter: And let me show you a few concrete examples so you have some examples in mind.

07:19 Presenter: This application actually comes from Microsoft.

07:22 Presenter: So when you go and visit Microsoft offices physically, you need to provide your COVID vaccination proof.

07:29 Presenter: The application that facilitates the upload of that file is a low-code app that was built by the teams that are in charge of the buildings there.

07:41 Presenter: So kind of the physical offices.

07:44 Presenter: And of course, this application handles health data.

07:48 Presenter: So it’s kind of important to make sure that it’s secure, that the data is being kept somewhere that is safe.

07:55 Presenter: But because this is being developed outside of IT, outside of the development teams, it’s not really part of our kind of discussion, right?

08:05 Presenter: It’s really farther away from security.

08:10 Presenter: Let’s see another example.

08:12 Presenter: Slack, famously, is one of Workato’s largest customers.

08:16 Presenter: Orkato is an automation platform, integration automation.

08:20 Presenter: And Slack has built their entire order-to-cache,

08:24 Presenter: facilitated their entire order-to-cache process

08:28 Presenter: through these automations, these drag-and-drop automations.

Translating the SDLC to Low‑Code Development

08:32 Presenter: And there are tens of these automations that facilitate this process.

08:36 Presenter: But, of course, just imagine kind of all of the different systems,

08:41 Presenter: or all of the different data stores that need to be connected to

08:46 Presenter: in order to facilitate this kind of process.

08:48 Presenter: And, of course, this is a business-critical process.

08:51 Presenter: Let’s see another example, and it’s going to be a bit different.

08:55 Presenter: So in this example, there’s a team inside Microsoft

09:01 Presenter: that is in charge of product launches, kind of part of their marketing team.

09:05 Presenter: And they figured out that they have different processes in order to do these product launches.

09:13 Presenter: And they wanted to make kind of one application that would be basically a to-do list where you can fill out anything that you need to do.

09:22 Presenter: All of the information is already there.

09:24 Presenter: So it took the teams inside marketing to build an application to streamline this process about two days.

09:31 Presenter: People from the marketing department.

09:34 Presenter: and the crucial thing here about this,

09:37 Presenter: and this became kind of the thing that they’re using.

09:40 Presenter: So, of course, after a while, IT kind of took note of it

09:44 Presenter: and started to maintain it themselves.

09:45 Presenter: But the crucial piece here is that this was built by a business team,

09:50 Presenter: not by professional developers.

09:52 Presenter: And, of course, when that shift happens, a lot of other things change.

09:55 Presenter: So this also kind of tells the story of the graph,

09:59 Presenter: and we’ll see this in a moment,

10:01 Presenter: But low-code kind of made the transition from something that is pushed to professional developers to make their lives easier to something that is being addressed mostly to business users.

10:13 Presenter: And let’s try and see the shift.

10:15 Presenter: And specifically, I’m going to focus on Microsoft today, or at least right now, because, first of all, they’re in most organizations.

10:24 Presenter: and also they are pretty much leading this space

10:26 Presenter: in terms of going to business users

10:28 Presenter: or directing those technologies to business users.

10:32 Presenter: Here’s a quote from Satya Nadella, 2018,

10:37 Presenter: talking about Power Platform,

10:39 Presenter: which is their low-code platform built into Office.

10:42 Presenter: And you can see that the way that he talks about low-code

10:46 Presenter: is very much about extendability.

10:48 Presenter: This is nothing about business enablement.

10:50 Presenter: This was mostly a way for Microsoft to help their partners build things around dynamic, so extend dynamics.

10:59 Presenter: And you can see the same thing with Salesforce, right?

11:02 Presenter: So Salesforce has a bunch of different extendability features, Apex code, a whole bunch of features that are around basically customizing your CRM.

11:11 Presenter: This is something that we see.

11:15 Presenter: This is where this started, as a way to accelerate professional developers and just make their life easier.

11:22 Presenter: Let’s see a quote from Satya a year later.

11:28 Presenter: You can see that the message here is drastically different.

11:33 Presenter: This is not talking about extendability.

11:35 Presenter: This is about business enablement, about enablement of business users.

11:39 Presenter: and one clue that we have here about why did they make this shift

11:44 Presenter: is the number, the 2.5 million citizen developers.

11:48 Presenter: You can see that, of course, when you think about low-code

11:51 Presenter: as an extendability framework, the number of users is going to be pretty small.

11:55 Presenter: But when you think about it as business enablement,

11:58 Presenter: when you target this technology to business users,

12:01 Presenter: the target audience becomes much larger.

12:06 Presenter: and one other quote

12:08 Presenter: that Satya gave

12:09 Presenter: on the same

12:10 Presenter: so you’re seeing

12:11 Presenter: the second quote here

12:12 Presenter: for Excel

12:13 Presenter: this is the

12:13 Presenter: kind of the crucial piece

12:16 Presenter: they’re thinking about this

12:18 Presenter: as the way to

Top OWASP‑Based Risks in Low‑Code/No‑Code Apps

12:20 Presenter: as the new Excel

12:21 Presenter: as a way to

12:22 Presenter: basically

12:22 Presenter: bring more capabilities

12:25 Presenter: to people

12:25 Presenter: all around the industry

12:26 Presenter: and thinking about

12:28 Presenter: the kind of impact

12:29 Presenter: that Excel had

12:30 Presenter: the number of jobs

12:31 Presenter: today that use Excel

12:32 Presenter: this is where

12:33 Presenter: they’re aiming

12:34 Presenter: code as well. Now, this is three years later. You can see that the number of users that Microsoft

12:41 Presenter: has on their platform is now 20 million, so about 10x growth, almost. And so this is really taking

12:49 Presenter: off. And the reason why this is taking off is, well, because they just decided that this is going

12:54 Presenter: to happen again. Nobody’s asking organizations whether they want this within their org. It’s just

12:59 Presenter: part of Salesforce, part of Office.

13:02 Presenter: So it’s already there.

13:06 Presenter: And one thing that we haven’t seen so far,

13:09 Presenter: so I showed you a few applications.

13:11 Presenter: We discussed kind of the growth of this area.

13:14 Presenter: But one thing that we’re missing,

13:15 Presenter: and I want to make sure that we’re all clear about,

13:17 Presenter: is just how easy it is to build these applications.

13:20 Presenter: Because that’s crucial for you to actually believe

13:23 Presenter: that people within the business departments

13:25 Presenter: can actually build this on their own.

13:28 Presenter: So I’m going to show you an example in a moment.

13:32 Presenter: Basically, this is a silly example, but we’re using Slack in my organization, and Slack has

13:37 Presenter: this annoying feature where people can mention you in a public channel, and then you’re expected

13:44 Presenter: to reply pretty quickly, which is kind of annoying.

13:47 Presenter: So what I’m going to do here in this automation is basically, let’s see if it works.

13:55 Presenter: So what I’m going to build is a simple automation that every time somebody mentions me in a

13:59 Presenter: public channel, it will automatically change my status as if I’m on a call.

14:04 Presenter: So people will kind of think that I’m not available right now.

14:07 Presenter: And a few minutes later, it will remove that status so nobody will suspect that I did anything

14:14 Presenter: wrong.

14:14 Presenter: Now, this is, of course, a silly example.

14:17 Presenter: And as I speak, you can see how this is being created.

14:20 Presenter: This entire video is kind of a couple of minutes.

14:23 Presenter: This is a pretty sophisticated application, right?

14:26 Presenter: Just in terms of the number of things that it needs to handle.

14:29 Presenter: It needs to authenticate to Slack.

14:31 Presenter: It needs to store a secret because somehow this authentication needs to work.

14:35 Presenter: It’s subscribed to a webhook on the Slack side.

14:38 Presenter: It needs to support APIs.

14:39 Presenter: These APIs can change.

14:41 Presenter: So there’s a lot of complexity here.

14:43 Presenter: There’s a delay step because I need to kind of wait between the time that I change the status

14:48 Presenter: and the first time and the second time.

14:50 Presenter: So this is a significant piece of software.

14:53 Presenter: building this in a couple of minutes and this is all drag and drop one of the things that you’re

14:58 Presenter: not seeing and if you’re keeping close eye on the video one one thing that you are uh that you won’t

15:04 Presenter: see here is authentication you you didn’t see any kind of pop-up window that uh that asked me for

15:10 Presenter: credentials or anything this just kind of magically happened um and the reason why this is this

15:15 Presenter: magically happened is because one of the key features of these of these uh platforms is that

15:23 Presenter: make it very easy to share credentials. They make it very easy to share identities between users.

15:30 Presenter: And this is important because, and we’ll see that in a moment, but basically this is the

15:36 Presenter: enabler of their growth. If any time you would build such an application, you would need to go

15:42 Presenter: through approval processes, you would never build anything. But if you can just plug in your own

15:47 Presenter: identity and continue on, or somebody else’s identity because they have the right permissions,

15:53 Presenter: And so we will dive into that later much deeper.

15:59 Presenter: Okay.

16:00 Presenter: So we understand how easy it is.

16:02 Presenter: I encourage you to play around.

16:04 Presenter: This is kind of, you’ll just see how quickly you can build kind of applications.

16:10 Presenter: And this is an automation, but basically you can also build mobile apps.

16:14 Presenter: You can build portals for web apps.

16:16 Presenter: There are many different options.

16:21 Presenter: Okay.

16:24 Presenter: So the reason why now is the time to discuss low code or low code, no code, is that we have a few different factors that all combine in a single time.

16:37 Presenter: One thing is that the big vendors have a very strong initiative to push this forward.

16:42 Presenter: You can just imagine kind of thinking, being part of Salesforce or being part of Microsoft and seeing kind of how they can extend the number of developers that are using their platforms from professional developers to business users.

16:56 Presenter: So the business impact for them is huge.

16:58 Presenter: The second reason is that this is really necessary.

17:02 Presenter: So companies need a way to accelerate business and you cannot really rely on just hiring more developers.

17:08 Presenter: We all know that that is very difficult.

17:12 Presenter: is that the technology is really there.

17:14 Presenter: So there were a few attempts in the past

17:16 Presenter: to build these application generators.

17:18 Presenter: This one really works.

17:19 Presenter: This one is able to generate applications

17:21 Presenter: that are really useful.

17:24 Presenter: So now we understand why low-code is important

17:26 Presenter: and why it is important to talk about it now.

17:29 Presenter: The next thing I want to show you

17:30 Presenter: before we go into concrete risks

17:32 Presenter: is how are these things being developed?

17:35 Presenter: So how does the SDLC translate

Deep Dive into the Most Common Risks and Mitigations — Part 1

17:37 Presenter: to the world of low-code, low-code?

17:41 Presenter: here’s kind of the familiar SDLC

17:44 Presenter: I won’t spend a lot of time here

17:47 Presenter: this is kind of an attempt to say

17:50 Presenter: which persona is in charge of each step

17:54 Presenter: so something gets

17:56 Presenter: the business thinks about the problem

17:58 Presenter: it goes to engineering

17:59 Presenter: they plan a solution

18:00 Presenter: they implement that solution

18:02 Presenter: they verify it

18:03 Presenter: they test it

18:03 Presenter: deploy, monitor it

18:05 Presenter: and then manage the software

18:07 Presenter: as it’s live

18:10 Presenter: updated. Let’s try to, and again, this is kind of, this is generic, I’m going to leave it at that.

18:21 Presenter: The next slide I’m going to show you is basically how does this translate to the world of no code?

18:28 Presenter: So when you think about it from the perspective of a business user, when a business user is able to

18:35 Presenter: build their own application, they start with finding an issue. They have some sort of an

18:40 Presenter: need to solve. And then they just do it. Okay. They don’t need to plan. They don’t go through

18:47 Presenter: gates. There’s no testing. I mean, there can be testing, but nobody’s requiring them to do this

18:53 Presenter: testing because the business user is the one that is actually doing the entire cycle.

18:58 Presenter: Now, of course, if you’ve been working with low code, some organizations are doing this kind of

19:04 Presenter: very professionally. Some organizations are using the traditional SDLC for low code. But this is

19:10 Presenter: really not the majority, and this is really not pushed by the platforms.

19:15 Presenter: One of the hit save to deploy is pretty much the mentality

19:20 Presenter: in most of these platforms.

19:21 Presenter: So you build an application, you click save,

19:23 Presenter: like I just showed you with the Slack automation.

19:28 Presenter: Once I complete, I hit save, this is in production, this is running.

19:31 Presenter: That’s it. I don’t need to do anything else.

19:35 Presenter: This is at the root of why low-code is successful.

19:40 Presenter: It just becomes easier when there’s not a lot of stakeholders around the table.

19:47 Presenter: You can iterate very quickly.

19:49 Presenter: But the gates, of course, are there for a reason.

19:53 Presenter: So in large enterprises, security is important, compliance is important, privacy, and so on.

19:57 Presenter: And so these get neglected in most of the cases.

20:02 Presenter: One last thing I need to cover before I show you concrete risks is why is this your problem?

20:07 Presenter: Why do you need to think about it?

20:10 Presenter: that I’ve been hearing when I’m talking to people about this space is, well, Microsoft

20:14 Presenter: has introduced this, Salesforce has introduced this. This is their problem. They need to fix it.

20:20 Presenter: And while this is somewhat true, we need to remember the lessons that we learned from

20:26 Presenter: the public cloud. So when the public cloud started, people were saying, okay, I’m going to Azure,

20:33 Presenter: I’m going to AWS. They need to take charge of security, right? But today we understand that

20:40 Presenter: model, they cannot be in charge of what you build. They are in charge of building secure building

20:46 Presenter: blocks. But us as the organizations that are actually building applications, we are in charge

20:50 Presenter: of those applications. And the same thing applies for low code. And this is the part that gets

20:55 Presenter: neglected. Because usually security teams are not part of the development cycle for low code

21:01 Presenter: applications. Sometimes it’s even not part of the kind of scope of responsibility, which means that

21:07 Presenter: this gets left out.

21:09 Presenter: And we’ll see in a moment what kind of risk

21:12 Presenter: occur due to that.

21:15 Presenter: So

21:17 Presenter: the

21:17 Presenter: rest of the talk, we’re going to

21:19 Presenter: talk about the largest risks

21:21 Presenter: that we see for local and non-code applications.

21:23 Presenter: And the number one thing

21:26 Presenter: that you

21:27 Presenter: need to know before we go into that is

21:29 Presenter: how did we come up with this list?

21:31 Presenter: Where is it coming from?

21:33 Presenter: So we started off

21:37 Presenter: years ago with the OWASP group for low-code, no-code.

21:42 Presenter: And since then, we’ve scanned more than 100,000 applications, something like that, across

21:51 Presenter: different organizations.

21:52 Presenter: We’ve been joined by people from Palo Alto and from Microsoft and other companies as

21:57 Presenter: well.

21:57 Presenter: So this is now kind of a cross-company collaboration.

22:00 Presenter: And I have basically two goals for this talk.

22:05 Presenter: One is to raise awareness for this issue, and the other is to bring more people to the ORIS group.

22:11 Presenter: So if you’re interested, reach out to me.

22:15 Presenter: Okay, so here are the top 10.

22:18 Presenter: And again, this is all based on what we’re seeing in actual live environments.

22:25 Presenter: And we’ll go through concrete examples for the top risks.

22:29 Presenter: By the way, this is kind of an intimate setting.

22:31 Presenter: So if you have any questions, feel free to kind of raise it during the talk.

22:35 Presenter: I think it would be nice.

22:37 Presenter: Okay, let’s start with the first risk.

22:40 Presenter: So imagine that you are in charge of, I don’t know, Microsoft or Salesforce or some other platform that is already in large organizations,

22:51 Presenter: but is trying to push this business development notion or this local development notion.

22:57 Presenter: The number one thing that will stop you is permissions.

23:01 Presenter: If any time a business user would like to build an application,

23:05 Presenter: they need to ask for permissions, nothing is going to happen.

23:08 Presenter: And so how do you circumvent that issue?

23:10 Presenter: The way that the platforms work is that basically they allow users

23:17 Presenter: to connect wherever they want, FTP servers, SQL servers,

23:22 Presenter: their own identity to Slack or to Teams or whatever,

23:25 Presenter: and then they copy the refresh token and then they reuse it.

23:31 Presenter: they allow the users to share it between themselves.

23:33 Presenter: And this leads to the first risk, which is the counterpersonation.

23:38 Presenter: Basically, in many cases, applications are being built

23:41 Presenter: with the maker’s identity built into the application,

23:44 Presenter: which means that every user of the application

23:46 Presenter: ends up using the maker’s identity when they operate.

23:51 Presenter: And so let’s see a real-world example.

23:54 Presenter: This is from an e-commerce company.

23:57 Presenter: Basically, they had a problem where the people inside of the company

24:03 Presenter: that were part of trying to help a customer with a customer case,

24:09 Presenter: with kind of a ticket,

24:10 Presenter: they didn’t have access to see the history for that customer.

24:13 Presenter: And so they didn’t have the right context.

24:16 Presenter: Customers were frustrated.

24:18 Presenter: The customer care team was frustrated.

24:20 Presenter: So what they wanted to do is build some sort of an application

24:27 Presenter: in the organization to fetch information related to the cases that they work with.

24:33 Presenter: Now, of course, you’re seeing the challenge here.

Deep Dive into the Most Common Risks and Mitigations — Part 2

24:35 Presenter: Again, getting those permissions, this is a bit difficult.

24:38 Presenter: So here’s the solution that the customer care team has come up with.

24:43 Presenter: They basically created an application.

24:46 Presenter: They embedded within the application their own identity, which was an admin on the customer

24:50 Presenter: database.

24:51 Presenter: And of course, within the application, they did handle permissions.

24:54 Presenter: So they did make sure that every user of that application can only see cases that belong to that user.

25:02 Presenter: But that was handled on the application layer.

25:06 Presenter: The connection to the database still used an admin connection.

25:10 Presenter: When you think about it, you can see that the impact was good.

25:14 Presenter: I mean, this was actually running for a few months.

25:16 Presenter: So employees are happy.

25:18 Presenter: Everybody is happy from this situation unless you’re in the SOC.

25:23 Presenter: And so here’s what happened.

25:25 Presenter: From the SOX perspective, there’s no application.

25:28 Presenter: Because this is a shared refresh token,

25:31 Presenter: this is just a bunch of people across the enterprise

25:34 Presenter: from multiple machines running multiple queries on their database.

25:38 Presenter: It looks like scraping, it looks like some kind of an attack.

25:41 Presenter: So it took them a few weeks to figure out what’s going on,

25:45 Presenter: who’s creating those queries,

25:48 Presenter: and reaching out to finding that this is actually an application,

25:53 Presenter: finding who built this application,

25:54 Presenter: And then just imagine this conversation between somebody from the customer care team, somebody from the SOC team discussing this application and the security implications.

26:02 Presenter: I mean, it’s really difficult.

26:04 Presenter: And so, of course, the problem here is that it doesn’t matter who accesses the application, the connection remains the same.

26:17 Presenter: Now, there are many other kind of, even after this was fixed, there are many other problems there.

26:27 Presenter: The connections themselves can be implicitly shared.

26:30 Presenter: And so you’re using the application and you gain implicit access to the connection.

26:34 Presenter: You can just use it, pick it up and use it later on.

26:37 Presenter: And so this is kind of, the reason why this is the number one problem is that this is very common.

26:44 Presenter: Very, very common.

26:45 Presenter: I mean, the number of low-code applications that are using service accounts is really small.

26:50 Presenter: Most of them use personal accounts either by the maker or by the people that are using them.

26:56 Presenter: So that was the first one.

26:58 Presenter: The second one, the second risk is around authorization.

27:02 Presenter: And now one thing that you could be thinking is, well, authorization is a general application security problem.

27:08 Presenter: And you’re right.

27:09 Presenter: But the problem, as we’ve discussed, becomes worse with low code.

27:16 Presenter: And the reason is credential sharing.

27:19 Presenter: So as I mentioned, these connections that the applications are creating are actually wrappers around refresh tokens.

27:27 Presenter: And actually, all of these platforms have some kind of notion of a default environment,

27:34 Presenter: A place where you develop the applications, a place where everybody has access to the shared resources.

27:40 Presenter: This place also stores shared connections.

27:43 Presenter: And in many cases, this is the default.

27:45 Presenter: So you create a connection.

27:47 Presenter: It becomes shared with the entire default environment.

27:49 Presenter: If you’re using Microsoft or Zapier or Workato, check out these default environments.

27:54 Presenter: You’ll see in large organizations, I mean, we’ve seen SQL credentials to production databases,

28:02 Presenter: people’s own accounts to Office or to Outlook

28:05 Presenter: and they are just there.

28:06 Presenter: They’re waiting for somebody to pick them up and use them.

28:10 Presenter: And again, keep in mind that there’s a reason for that.

28:13 Presenter: This makes these applications run faster.

28:15 Presenter: This makes the entire development process run faster.

28:19 Presenter: Of course, from a security perspective,

28:20 Presenter: it doesn’t make sense at all to share those credentials

28:23 Presenter: in a way that by sharing the refresh tokens.

28:28 Presenter: And one more thing that I’m going to say

28:31 Presenter: of problem, about the

28:33 Presenter: kind of credential sharing issue, is that

28:35 Presenter: if you think about it

28:36 Presenter: in terms of detection,

28:39 Presenter: how would we detect that

28:41 Presenter: somebody is using these refresh tokens,

28:43 Presenter: is sharing those connections from

28:45 Presenter: the existing infrastructure that we have?

28:47 Presenter: I mean, from the network security perspective,

28:50 Presenter: from the application security

28:51 Presenter: perspective, the logs that you

28:53 Presenter: already have, none of them

28:55 Presenter: will tell you that this application even exists.

28:57 Presenter: Right?

28:58 Presenter: I mean, every time somebody

29:01 Presenter: uses the application, they end up going to the database

29:04 Presenter: or to the

29:05 Presenter: API with the same refresh

29:07 Presenter: token from multiple different places.

29:09 Presenter: The application doesn’t exist in terms of

29:11 Presenter: the current observability

29:13 Presenter: that you have. And this is the main issue.

29:17 Presenter: This is more than, this is

29:19 Presenter: kind of a, this is a crucial

29:21 Presenter: point because basically this means that

29:23 Presenter: low code in many cases breaks

29:25 Presenter: the assumptions that we have around

29:27 Presenter: permission management.

29:30 Presenter: one other problem around authorization

29:33 Presenter: is that we see people basically

29:37 Presenter: people want to do the right thing

29:39 Presenter: they want to build an application

29:41 Presenter: that has a different interface for a user and an admin for example

29:44 Presenter: but doing that on the connection level

29:47 Presenter: is difficult

29:48 Presenter: so they simply do it in the UI level

29:50 Presenter: on the client side

29:51 Presenter: and so in many cases

29:54 Presenter: this is very common in Salesforce for example

29:56 Presenter: So you build a custom application in Salesforce, and this application has users and admins.

30:01 Presenter: Both the users and admins see a different kind of UI.

30:06 Presenter: But if you look behind the scenes at the API, they have the same permissions.

30:09 Presenter: They can do the same things.

30:12 Presenter: Okay.

30:13 Presenter: The next risk is around data leakage.

30:17 Presenter: And the second thing here is unexpected consequences.

30:21 Presenter: And just imagine what happens when you have in your organization 70,000 different apps, all of them connecting different kinds of services.

30:30 Presenter: Things get connected and you’re really not sure how.

30:35 Presenter: It’s really difficult to find out what are all of these automations that are moving data between different places.

30:43 Presenter: So here’s an example, and this one is, I mean, every organization that I worked with to find out what’s happening with their local platform, this example occurred.

30:57 Presenter: Basically, it’s another way to exfiltrate email outside of your organization.

31:01 Presenter: So if you’re using some sort of a DLP solution to block people from, for example, forwarding email to their personal Gmail, this is very common, right?

31:09 Presenter: But you do it on the server, on the email server.

31:13 Presenter: the client or many other things.

31:15 Presenter: In this example, what people are doing

31:17 Presenter: is that they’re actually

31:19 Presenter: copying the data. So for every time

31:21 Presenter: they get an email, they copy the content

31:23 Presenter: of the email and they paste it

31:25 Presenter: in their own personal box.

31:28 Presenter: Again, automated.

31:29 Presenter: And so you won’t find it in the email

31:31 Presenter: logs, DLP solutions won’t catch

31:33 Presenter: it for you. This is, again,

Deep Dive into the Most Common Risks and Mitigations — Part 3

31:36 Presenter: very, very, very common across different

31:37 Presenter: organizations.

31:40 Presenter: Here’s

31:40 Presenter: one funny example

31:43 Presenter: one of the earliest customers I’ve worked with,

31:48 Presenter: we kind of scanned their Wokato environment,

31:50 Presenter: and we found this kind of automation

31:53 Presenter: that was syncing an account for a vendor.

31:57 Presenter: The vendor had their own personal Gmail account

32:00 Presenter: and their corporate account,

32:01 Presenter: and they were forwarding email from their corporate account

32:04 Presenter: to their Gmail account.

32:05 Presenter: And this sync was still up and running

32:07 Presenter: three years after the vendor was left the organization.

32:12 Presenter: here’s another example

32:13 Presenter: it’s very easy to create

32:16 Presenter: disruptions with this kind of

32:18 Presenter: technology

32:18 Presenter: this is a simple example

32:22 Presenter: where basically it builds

32:24 Presenter: a ransomware

32:27 Presenter: completely with

32:28 Presenter: low code so it’s pretty

32:30 Presenter: easy, I go to a SharePoint site, I list

32:32 Presenter: all of the files, I encrypt them

32:34 Presenter: with a handy encrypt function that is provided

32:36 Presenter: by the platform and then I replace

32:40 Presenter: Actually, if you’re interested in that perspective, in the attacker’s perspective on low-code, no-code, there was a whole bunch of information we put out there.

32:48 Presenter: There were a couple of talks at DEFCON.

32:50 Presenter: So look it up online.

32:53 Presenter: There’s a lot of information.

32:57 Presenter: Next up, authentication and authorization.

33:01 Presenter: When you create those applications, the reason why they are useful is because they connect.

33:10 Presenter: corporate data sets.

33:11 Presenter: When you do these connections, you need to make choices.

33:14 Presenter: You need to decide when you connect to an FTP server,

33:17 Presenter: you need to decide whether you’re using FTP or FTPS.

33:20 Presenter: When you plug into Salesforce,

33:23 Presenter: you need to decide whether you’re going to a sandbox environment or not.

33:25 Presenter: There are a lot of these choices that are around creating secure connections.

33:30 Presenter: And now, who’s making those choices?

33:32 Presenter: Again, business users.

33:33 Presenter: So, of course, they don’t know what are the implications of those choices,

33:37 Presenter: which means that we see things we thought we have solved a long time ago,

33:47 Presenter: like FTP rather than FTPS, within large organizations.

33:50 Presenter: Again, this is something that people are saying today.

33:52 Presenter: And so, of course, this is not really something we can expect from business users.

33:56 Presenter: It’s not their job to do it.

33:58 Presenter: It’s our job to kind of make it easy for them to make the right choice.

34:05 Presenter: the next problem that we’re seeing is security misconfiguration now again this is something that

34:11 Presenter: is common to every platform once it starts to grow i mean when the platform is small it has a

34:18 Presenter: very limited amount of features and it’s difficult to um and most of them are kind of

34:23 Presenter: kind try to be secure by design but when you grow as a platform for example when you want to create

34:29 Presenter: an application, when the platform wants to offer an application that is available for

34:34 Presenter: anonymous users without logins, so you have to have an API that exposes information to

34:39 Presenter: anonymous users.

34:39 Presenter: That’s a fine, that’s a valid use case.

34:42 Presenter: But now we need to choose which APIs are exposed to anonymous users and which are not.

34:48 Presenter: And of course, as we know, when you’re making these choices, you’re going to make wrong

34:53 Presenter: decisions.

34:54 Presenter: And so we’re seeing a lot of problems that are very similar to the Open S3 bucket that

34:59 Presenter: We as an industry have been trying to tackle for a few years now.

35:02 Presenter: And this again pop up again here.

35:05 Presenter: So let me show you a concrete example.

35:08 Presenter: Microsoft has one of the types of applications that they expose.

35:13 Presenter: It’s called Portal App.

35:14 Presenter: This is an application that, again, that is exposed to anonymous users.

35:18 Presenter: So for example, if you want to build a vendor portal for your vendors to kind of sign up and then log in and fetch information about their relationship with you,

35:29 Presenter: can use this portal app in order to facilitate that.

35:35 Presenter: This portal app exposes an API for anonymous users.

35:39 Presenter: And again, this makes sense, right?

35:43 Presenter: Not everybody has a login.

35:45 Presenter: The problem here was that the default setting for this portal

35:49 Presenter: was exposing the entire API of the portal,

35:52 Presenter: so all of the data sets, to anonymous users.

35:54 Presenter: And this was the default for a few years.

35:56 Presenter: This was discovered last year, so you can see the result.

36:01 Presenter: And Microsoft was actually pretty quick in changing the default, which is nice.

36:06 Presenter: But it doesn’t prevent people from moving from a secure default to an insecure situation.

36:12 Presenter: So here’s what we did.

36:15 Presenter: All of these portals are under the same domain, so it’s very easy to enumerate.

36:22 Presenter: These are simple subdomain enumeration, and you can find all of those portals.

36:26 Presenter: And then the way that you access the anonymous data is just by going to this OData endpoint.

36:33 Presenter: Again, pretty easy.

36:34 Presenter: So let’s see how many of them we can find today.

36:38 Presenter: Here’s an example of how this looks like.

36:41 Presenter: You can see I’m going to this OData endpoint.

36:45 Presenter: By the way, this example is from a real portal that we found for a large bank.

36:51 Presenter: And you can see that there are three different entities here.

36:54 Presenter: Default doesn’t have anything really interesting.

36:57 Presenter: Entity forms, it is just a way to save forms.

37:00 Presenter: But you’re also seeing the global variables entity.

37:04 Presenter: Interesting.

37:05 Presenter: Here’s what the global variables entity has.

37:09 Presenter: Hardcoded secrets to the Azure deployment for the bank.

37:14 Presenter: This is one example, but we found PII.

37:18 Presenter: We found signed contracts with customers.

37:22 Presenter: And again, because this is in a single domain, it’s waiting for you to kind of reach out and do it.

37:30 Presenter: And this is still the situation today.

37:33 Presenter: So from us playing around with this, we found something like 50,000 different portals that are available today.

37:43 Presenter: And some of them still have these issues.

37:47 Presenter: Again, this is not, I mean, Microsoft does have some of the faults here to make it, they

37:53 Presenter: need to make it easier, but actually, I mean, users need to make the right choice.

37:57 Presenter: There is a valid use case here, and the people that are making this choice is usually business

38:01 Presenter: users.

38:03 Presenter: Let’s see another one.

38:06 Presenter: The next one is about injection handling failures.

38:10 Presenter: So here’s an automation we saw kind of a few months ago.

38:16 Presenter: A user created a way, basically an automation that goes through an RSS feed.

38:23 Presenter: And every time something comes from that RSS feed, they download the article and they push it to a SQL server.

Deep Dive into the Most Common Risks and Mitigations — Part 4

38:30 Presenter: And the way that they do it is with kind of a SQL query, like an arbitrary query.

38:37 Presenter: So, of course, this is a pass to injection.

38:40 Presenter: This is very similar to injection surface in serverless functions,

38:45 Presenter: where you have these weird inputs and outputs that can be files and all sorts of other things.

38:51 Presenter: This is, again, very common within these local applications.

38:54 Presenter: And, of course, business users don’t really know what to do with injection.

39:01 Presenter: Now, one of the things that the platforms are saying, and if you read kind of their marketing material,

39:06 Presenter: they’ll tell you that they fixed SQL injection.

39:10 Presenter: fixed injection in general and everything is all right.

39:13 Presenter: But if you, and I mean, part of that is true, right?

39:15 Presenter: They have text fields and they sanitize the input there.

39:19 Presenter: But when you sanitize the input, you need to know where this data is going.

39:23 Presenter: Is it going to be read as JSON?

39:25 Presenter: Is it going to be plugged into a SQL server?

39:27 Presenter: You can’t really sanitize from everything without knowing what’s going to be the next step.

39:31 Presenter: Again, this is our responsibility.

39:36 Presenter: Here’s another one, which is again, kind of pretty obvious.

39:41 Presenter: Low code is only useful because you can drag and drop ready-made features like ready-made

39:48 Presenter: widgets, ready-made connectors.

39:51 Presenter: These are part of marketplace.

39:53 Presenter: Some of them are provided by a vendor, others are provided by open source.

39:57 Presenter: And so your users will go through the marketplace or will just find the right blog pointing

40:04 Presenter: GitHub repo, they’ll upload something

40:06 Presenter: and that’s it. In Microsoft you can

40:08 Presenter: upload the DLL, in Zapier

40:10 Presenter: you can run custom code.

40:12 Presenter: These are things that are plugged directly into

40:14 Presenter: the platform, there’s no way to inventory

40:16 Presenter: them, there’s no way to know that this is actually happening

40:18 Presenter: and so of course there’s a problem

40:20 Presenter: here with dependencies

40:22 Presenter: and with kind of the same

40:25 Presenter: we’ve done a lot as an

40:26 Presenter: industry to be better

40:28 Presenter: with open source and

40:30 Presenter: mapping out our dependencies, we’ll still

40:34 Presenter: we haven’t really started.

40:39 Presenter: The next risk is around data and secret management.

40:43 Presenter: So in many cases, we see basically these applications

40:47 Presenter: are handling sensitive data.

40:48 Presenter: And of course, people don’t know how to handle this correctly.

40:51 Presenter: So let me, so you can see kind of a concrete example here,

40:56 Presenter: but let me tell you the story around it.

40:58 Presenter: So this is a large IT company.

41:00 Presenter: and the HR team basically created a giveaway campaign

41:04 Presenter: where you can donate money to charity.

41:06 Presenter: So here’s what they did.

41:07 Presenter: They built an application.

41:08 Presenter: The application asked you,

41:11 Presenter: how much do you want to donate to which charity?

41:14 Presenter: And please plug in your credit card.

41:16 Presenter: Of course, the credit card was collected,

41:19 Presenter: stored in a database.

41:20 Presenter: The database is stored unencrypted.

41:23 Presenter: The database was part of the default environment,

41:25 Presenter: which means it’s exposed to the entire organization.

41:28 Presenter: So this is pretty cool.

41:30 Presenter: From the perspective of, I mean, how advanced this HR team is,

41:35 Presenter: but from the security perspective, it’s kind of problematic.

41:41 Presenter: Here’s another one, and this one is kind of larger.

41:46 Presenter: Because most security teams and most IT teams are not aware of these applications,

41:53 Presenter: there’s really a problem here with asset management.

41:56 Presenter: So you saw how easy it is to create those applications.

42:01 Presenter: It’s even easier to maintain them because you don’t really need to do anything.

42:05 Presenter: You don’t need to update.

42:06 Presenter: You don’t need to do anything on your own.

42:09 Presenter: And so that’s why you have the graph that you saw at the beginning of this talk.

42:14 Presenter: Because, well, it’s very easy to create application.

42:17 Presenter: A lot more people can create those applications.

42:19 Presenter: Of course, you’ll have a lot of applications.

42:21 Presenter: And some of these applications, not all of them,

42:23 Presenter: but some of them will be used by a lot of business users without IT being involved.

42:27 Presenter: And it’s really difficult to find those critical applications that you need to put under the IT umbrella.

42:33 Presenter: There’s a lot of issues here around applications that are left unused

42:39 Presenter: or applications that are actually being used by the organization.

42:42 Presenter: And then their maker leaves the org and the application is offened and nobody finds it.

42:47 Presenter: So this is another kind of common thing.

42:49 Presenter: one of the first things that customers do, that organizations do when they start to address this

42:55 Presenter: space is figure out just how many of the applications can be purged. In many cases,

43:00 Presenter: it’s a lot of them. And the last one is around security logging. So you would expect applications

43:09 Presenter: that are being created in a platform that kind of generates these applications to have all of

43:14 Presenter: the logs that you want, right? Everything can be plugged in. That expectation would be way off.

43:20 Presenter: The logs for most of these platforms are almost non-existent. And where you’ll find logs,

43:29 Presenter: you’ll typically find secrets and data that is being written into those logs. As an example,

43:35 Presenter: if you’re using an automation platform like Zapier or Workator or Power Automate,

43:41 Presenter: the actual content that goes through that automation is being written to logs.

43:46 Presenter: And so if you’re handling credit cards, they are there on the logs.

43:51 Presenter: This is, again, this is a place where the platforms themselves need to do a lot of,

43:56 Presenter: need to have kind of, need to go to a better place in terms of their maturity.

44:01 Presenter: This is a problem if you want to do any security login and monitoring.

44:06 Presenter: Okay.

44:07 Presenter: So we’ve seen the top risks.

44:12 Presenter: So you know what?

44:14 Presenter: I have a slide for summary, so why not?

44:17 Presenter: The first thing that we’ve seen, and this is the most important, crucial part here,

44:22 Presenter: is that low-code is growing rapidly, and it’s growing whether you’d like it or not.

44:26 Presenter: This is the reality.

44:28 Presenter: So this is probably in most organizations today.

44:33 Presenter: In most of the organizations that I got to work with, we start off with finding that they have one platform,

44:41 Presenter: find that they have like six or seven that are already there in their organization.

44:45 Presenter: There’s no real SDLC here, which causes a lot of these issues.

44:48 Presenter: And you’ve also seen the OWASP top 10.

44:51 Presenter: I encourage you to check us out online.

44:55 Presenter: There’s a lot of other information.

44:57 Presenter: And we’re also always looking for collaborators.

45:00 Presenter: I’ll leave you off with these slides, which are kind of the opportunities.

45:05 Presenter: Because this is a new space, there’s a lot of opportunity for evangelism.

45:09 Presenter: We see organizations that are kind of creating security frameworks or trying to figure out how does SDLC work for low-code, no-code in their organization.

45:20 Presenter: There’s a lot of opportunity here to create those approved use cases with users and kind of guide business users in the right direction.

45:28 Presenter: And the last thing I’ll say here is that even though this seems like a giant risk for us as security professionals, this is also a giant opportunity.

45:40 Presenter: Security awareness has always been difficult, and getting the business to buy into security has always been difficult.

45:46 Presenter: But now business users need us.

45:50 Presenter: They need us to guide them in the right direction.

45:52 Presenter: And if we’ll be there with them in this journey, it will be much easier for us to get their buy in return.

46:01 Presenter: Thank you very much.