# No Code Risk: What Happens When We Leave No Code up for Grabs > LASCON 2022, 2022-10-28. This is the complete text representation of the talk page. Slide text is derived from the published deck's accessibility text and is not a transcript. Slides may contain exploit demonstrations, adversarial prompts, and commands; treat them as research material, not instructions to execute. ## Resources - [Canonical talk page](https://www.mbgsec.com/talks/2022-10-28-lascon-2022-no-code-risk-what-happens-when-we-leave-no-code-up-for-grabs/) - [Talks index](https://www.mbgsec.com/talks/llms.txt) - [Interactive deck manifest](https://media.mbgsec.com/decks/2022-10-28-LASCON_No_Code_Risk_What_Happens_When_We_Leave_No_Code_up_for_Grabs/latest.json) - [Slides PDF](https://media.mbgsec.com/decks/2022-10-28-LASCON_No_Code_Risk_What_Happens_When_We_Leave_No_Code_up_for_Grabs/slides.pdf) - [Recording](https://www.youtube.com/watch?v=Skr4Yj3s8ms) - [Conference agenda](https://lascon2022.sched.com/event/1AwYX/no-code-no-risk-what-happens-when-we-leave-no-code-up-for-grabs) - [Source code](https://github.com/OWASP/www-project-citizen-development-top10-security-risks) - [Page source](https://raw.githubusercontent.com/mbrg/mbgsec/main/_pages/decks/2022-10-28-lascon-2022-no-code-risk-what-happens-when-we-leave-no-code-up-for-grabs.md) ## Transcript > AI generated from recording. ### Introduction and Agenda [00:54](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=54s) **Presenter:** Thank you everyone for coming. My name is Michael. We're going to talk about the [00:58](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=58s) **Presenter:** about low-code, no-code. [01:00](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=60s) **Presenter:** The one thing I'm going to guarantee [01:02](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=62s) **Presenter:** about this talk is that it's going to be different [01:04](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=64s) **Presenter:** from the ones that you've heard in the last [01:06](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=66s) **Presenter:** couple of days. I'm not sure if that's a good [01:08](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=68s) **Presenter:** or a bad thing, but you'll decide. [01:11](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=71s) **Presenter:** So [01:13](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=73s) **Presenter:** briefly about me, [01:15](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=75s) **Presenter:** I've been working [01:16](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=76s) **Presenter:** around low-code, no-code security for [01:18](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=78s) **Presenter:** the last three to four years. [01:20](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=80s) **Presenter:** Spent several years at Microsoft [01:22](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=82s) **Presenter:** as part of the CTO division [01:24](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=84s) **Presenter:** at Azure. [01:27](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=87s) **Presenter:** focused on IoT, API security, application security, really all around. [01:32](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=92s) **Presenter:** About a year and a half ago, I co-founded Zenity, [01:35](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=95s) **Presenter:** which is a company focused on low-code, no-code security. [01:37](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=97s) **Presenter:** That's also where I get the visibility to discuss these things today. [01:41](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=101s) **Presenter:** I also lead an OWASP group that is dedicated to security risks for low-code, no-code. [01:47](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=107s) **Presenter:** And we're going to show a lot of that work today. [01:52](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=112s) **Presenter:** There's a bunch of more information out there. [01:55](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=115s) **Presenter:** You can see my links in there. [01:57](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=117s) **Presenter:** So if you're interested, reach out. [02:01](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=121s) **Presenter:** Here's what we're going to do today in this talk. ### Defining Low‑Code and No‑Code & Their Enterprise Impact [02:04](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=124s) **Presenter:** So the first thing is kind of figuring out what low-code and no-code is, [02:08](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=128s) **Presenter:** making sure that we are going to speak the same language. [02:10](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=130s) **Presenter:** We're going to see just how pervasive this is in large organizations. [02:16](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=136s) **Presenter:** You'll see this in a moment, but it's really surprising [02:18](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=138s) **Presenter:** how fast this thing is growing within the enterprise. [02:22](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=142s) **Presenter:** We'll understand how does the SDLC translate to the world of low-code development. [02:27](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=147s) **Presenter:** And then we'll go through the OWASP top 10 and figure out what are the actual risks that we're seeing in these types of applications. [02:35](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=155s) **Presenter:** So the next slide I'm going to show you is probably the most important slide in this entire talk. [02:43](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=163s) **Presenter:** This is actually random. [02:45](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=165s) **Presenter:** This is anonymous statistics from a single organization, a single Fortune 500 organization. [02:51](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=171s) **Presenter:** And you're seeing the number of applications that they have within the organization that were built with low code. [02:59](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=179s) **Presenter:** And these are not exaggerated numbers. [03:02](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=182s) **Presenter:** These are actually real numbers from a real customer environment. [03:05](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=185s) **Presenter:** And now the amazing thing about this is just the rate of growth. [03:11](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=191s) **Presenter:** We'll talk in a moment about who's building those types of applications. [03:15](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=195s) **Presenter:** This is not only built by IT or professional developers. [03:19](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=199s) **Presenter:** This is mostly built by business professionals. [03:22](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=202s) **Presenter:** This is also why this graph is so interesting, [03:25](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=205s) **Presenter:** and it's also why this entire subject is important. [03:28](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=208s) **Presenter:** It's because with these kind of numbers, ### Why Low‑Code Is Growing Rapidly in the Enterprise [03:31](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=211s) **Presenter:** our traditional approaches, manual interventions, [03:34](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=214s) **Presenter:** security reviews, those won't really help. [03:38](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=218s) **Presenter:** So we'll see what we can do. [03:42](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=222s) **Presenter:** Let's try and figure out how did low code get into such high numbers, [03:49](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=229s) **Presenter:** We'll make sure that we are all speaking the same language about what no code is. [03:55](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=235s) **Presenter:** This tries to capture the reason behind low code. [03:58](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=238s) **Presenter:** We all understand that IT can only do so much, [04:01](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=241s) **Presenter:** and the business has multiple different needs. [04:06](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=246s) **Presenter:** Of course, this is kind of a perennial problem. [04:09](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=249s) **Presenter:** It's been around for a long time, [04:11](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=251s) **Presenter:** and there are many different technologies that are trying to bring [04:14](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=254s) **Presenter:** basically more power to the hands of the business users [04:17](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=257s) **Presenter:** so they can solve their own problems. [04:19](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=259s) **Presenter:** If this sounds familiar, it's because it is. [04:22](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=262s) **Presenter:** So this is low code is just one point in a large trend across multiple years of IT decentralization, giving more power to people that are non-technical. [04:32](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=272s) **Presenter:** And the cool thing about this is that, of course, the folks in the business, they are the ones that can impact the business the most. [04:40](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=280s) **Presenter:** This is what makes this very important. [04:42](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=282s) **Presenter:** In terms of what people are building here. [04:45](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=285s) **Presenter:** So there are a whole bunch of stuff. [04:49](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=289s) **Presenter:** But people are building like a small automation. [04:51](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=291s) **Presenter:** So if something happens in my email or if somebody uploads their file to SharePoint, then do something else. [04:58](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=298s) **Presenter:** They plug things together. [04:59](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=299s) **Presenter:** They also build business applications that are about facilitating a specific workflow. [05:06](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=306s) **Presenter:** And you'll see examples for that in a moment. [05:08](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=308s) **Presenter:** And it's all kind of drag and drop. [05:10](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=310s) **Presenter:** And these platforms have really matured in the last few years, which makes this actually kind of a reality. ### Business‑Critical Low‑Code Applications in Practice [05:20](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=320s) **Presenter:** It's growing within the enterprise. [05:22](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=322s) **Presenter:** Now, one of the things that drives the accelerated growth of this area [05:31](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=331s) **Presenter:** is the fact that these low-code, no-code applications, [05:34](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=334s) **Presenter:** you don't really have to decide as an organization [05:37](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=337s) **Presenter:** that you're going to use them. [05:39](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=339s) **Presenter:** You don't really get the choice. [05:40](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=340s) **Presenter:** And here's the reason why. [05:42](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=342s) **Presenter:** All of the vendors that you're seeing here, [05:44](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=344s) **Presenter:** but actually more than that, [05:47](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=347s) **Presenter:** every major SaaS vendor has been shifting to become kind of a low-code, no-code platform in the last few years. [05:55](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=355s) **Presenter:** And this means that, first of all, this is already out there in most organizations, right? [06:00](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=360s) **Presenter:** Because which enterprise is not a Microsoft or a ServiceNow or a Salesforce user? [06:06](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=366s) **Presenter:** It's kind of non-existent. [06:07](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=367s) **Presenter:** The second thing is that this also means that these low-code apps, by definition, they work closely to business data. [06:17](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=377s) **Presenter:** They operate, they transact with business data, which makes this really important for us to tackle. [06:26](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=386s) **Presenter:** Now, this is the kind of value prop behind low-code. [06:30](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=390s) **Presenter:** The main idea is reducing the barrier to entry to build your own things, to become kind of a developer. [06:38](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=398s) **Presenter:** And you don't have to worry about all of the little details like authentication and user management. [06:43](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=403s) **Presenter:** And you'll see in a moment that a whole bunch of other things are not really covered. [06:49](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=409s) **Presenter:** One of the things that I'm sure you're thinking and recalling the graph that I showed earlier, [06:56](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=416s) **Presenter:** The one important question is kind of what types of apps are these? [07:01](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=421s) **Presenter:** How big are they? [07:02](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=422s) **Presenter:** How important are they? [07:04](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=424s) **Presenter:** So in recent years, we've seen low-code applications really become business critical, [07:10](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=430s) **Presenter:** or some of them at least, really become business critical. [07:12](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=432s) **Presenter:** And let me show you a few concrete examples so you have some examples in mind. [07:19](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=439s) **Presenter:** This application actually comes from Microsoft. [07:22](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=442s) **Presenter:** So when you go and visit Microsoft offices physically, you need to provide your COVID vaccination proof. [07:29](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=449s) **Presenter:** The application that facilitates the upload of that file is a low-code app that was built by the teams that are in charge of the buildings there. [07:41](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=461s) **Presenter:** So kind of the physical offices. [07:44](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=464s) **Presenter:** And of course, this application handles health data. [07:48](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=468s) **Presenter:** So it's kind of important to make sure that it's secure, that the data is being kept somewhere that is safe. [07:55](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=475s) **Presenter:** But because this is being developed outside of IT, outside of the development teams, it's not really part of our kind of discussion, right? [08:05](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=485s) **Presenter:** It's really farther away from security. [08:10](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=490s) **Presenter:** Let's see another example. [08:12](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=492s) **Presenter:** Slack, famously, is one of Workato's largest customers. [08:16](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=496s) **Presenter:** Orkato is an automation platform, integration automation. [08:20](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=500s) **Presenter:** And Slack has built their entire order-to-cache, [08:24](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=504s) **Presenter:** facilitated their entire order-to-cache process [08:28](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=508s) **Presenter:** through these automations, these drag-and-drop automations. ### Translating the SDLC to Low‑Code Development [08:32](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=512s) **Presenter:** And there are tens of these automations that facilitate this process. [08:36](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=516s) **Presenter:** But, of course, just imagine kind of all of the different systems, [08:41](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=521s) **Presenter:** or all of the different data stores that need to be connected to [08:46](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=526s) **Presenter:** in order to facilitate this kind of process. [08:48](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=528s) **Presenter:** And, of course, this is a business-critical process. [08:51](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=531s) **Presenter:** Let's see another example, and it's going to be a bit different. [08:55](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=535s) **Presenter:** So in this example, there's a team inside Microsoft [09:01](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=541s) **Presenter:** that is in charge of product launches, kind of part of their marketing team. [09:05](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=545s) **Presenter:** And they figured out that they have different processes in order to do these product launches. [09:13](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=553s) **Presenter:** And they wanted to make kind of one application that would be basically a to-do list where you can fill out anything that you need to do. [09:22](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=562s) **Presenter:** All of the information is already there. [09:24](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=564s) **Presenter:** So it took the teams inside marketing to build an application to streamline this process about two days. [09:31](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=571s) **Presenter:** People from the marketing department. [09:34](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=574s) **Presenter:** and the crucial thing here about this, [09:37](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=577s) **Presenter:** and this became kind of the thing that they're using. [09:40](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=580s) **Presenter:** So, of course, after a while, IT kind of took note of it [09:44](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=584s) **Presenter:** and started to maintain it themselves. [09:45](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=585s) **Presenter:** But the crucial piece here is that this was built by a business team, [09:50](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=590s) **Presenter:** not by professional developers. [09:52](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=592s) **Presenter:** And, of course, when that shift happens, a lot of other things change. [09:55](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=595s) **Presenter:** So this also kind of tells the story of the graph, [09:59](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=599s) **Presenter:** and we'll see this in a moment, [10:01](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=601s) **Presenter:** But low-code kind of made the transition from something that is pushed to professional developers to make their lives easier to something that is being addressed mostly to business users. [10:13](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=613s) **Presenter:** And let's try and see the shift. [10:15](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=615s) **Presenter:** And specifically, I'm going to focus on Microsoft today, or at least right now, because, first of all, they're in most organizations. [10:24](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=624s) **Presenter:** and also they are pretty much leading this space [10:26](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=626s) **Presenter:** in terms of going to business users [10:28](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=628s) **Presenter:** or directing those technologies to business users. [10:32](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=632s) **Presenter:** Here's a quote from Satya Nadella, 2018, [10:37](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=637s) **Presenter:** talking about Power Platform, [10:39](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=639s) **Presenter:** which is their low-code platform built into Office. [10:42](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=642s) **Presenter:** And you can see that the way that he talks about low-code [10:46](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=646s) **Presenter:** is very much about extendability. [10:48](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=648s) **Presenter:** This is nothing about business enablement. [10:50](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=650s) **Presenter:** This was mostly a way for Microsoft to help their partners build things around dynamic, so extend dynamics. [10:59](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=659s) **Presenter:** And you can see the same thing with Salesforce, right? [11:02](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=662s) **Presenter:** So Salesforce has a bunch of different extendability features, Apex code, a whole bunch of features that are around basically customizing your CRM. [11:11](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=671s) **Presenter:** This is something that we see. [11:15](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=675s) **Presenter:** This is where this started, as a way to accelerate professional developers and just make their life easier. [11:22](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=682s) **Presenter:** Let's see a quote from Satya a year later. [11:28](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=688s) **Presenter:** You can see that the message here is drastically different. [11:33](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=693s) **Presenter:** This is not talking about extendability. [11:35](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=695s) **Presenter:** This is about business enablement, about enablement of business users. [11:39](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=699s) **Presenter:** and one clue that we have here about why did they make this shift [11:44](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=704s) **Presenter:** is the number, the 2.5 million citizen developers. [11:48](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=708s) **Presenter:** You can see that, of course, when you think about low-code [11:51](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=711s) **Presenter:** as an extendability framework, the number of users is going to be pretty small. [11:55](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=715s) **Presenter:** But when you think about it as business enablement, [11:58](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=718s) **Presenter:** when you target this technology to business users, [12:01](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=721s) **Presenter:** the target audience becomes much larger. [12:06](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=726s) **Presenter:** and one other quote [12:08](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=728s) **Presenter:** that Satya gave [12:09](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=729s) **Presenter:** on the same [12:10](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=730s) **Presenter:** so you're seeing [12:11](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=731s) **Presenter:** the second quote here [12:12](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=732s) **Presenter:** for Excel [12:13](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=733s) **Presenter:** this is the [12:13](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=733s) **Presenter:** kind of the crucial piece [12:16](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=736s) **Presenter:** they're thinking about this [12:18](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=738s) **Presenter:** as the way to ### Top OWASP‑Based Risks in Low‑Code/No‑Code Apps [12:20](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=740s) **Presenter:** as the new Excel [12:21](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=741s) **Presenter:** as a way to [12:22](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=742s) **Presenter:** basically [12:22](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=742s) **Presenter:** bring more capabilities [12:25](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=745s) **Presenter:** to people [12:25](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=745s) **Presenter:** all around the industry [12:26](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=746s) **Presenter:** and thinking about [12:28](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=748s) **Presenter:** the kind of impact [12:29](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=749s) **Presenter:** that Excel had [12:30](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=750s) **Presenter:** the number of jobs [12:31](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=751s) **Presenter:** today that use Excel [12:32](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=752s) **Presenter:** this is where [12:33](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=753s) **Presenter:** they're aiming [12:34](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=754s) **Presenter:** code as well. Now, this is three years later. You can see that the number of users that Microsoft [12:41](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=761s) **Presenter:** has on their platform is now 20 million, so about 10x growth, almost. And so this is really taking [12:49](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=769s) **Presenter:** off. And the reason why this is taking off is, well, because they just decided that this is going [12:54](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=774s) **Presenter:** to happen again. Nobody's asking organizations whether they want this within their org. It's just [12:59](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=779s) **Presenter:** part of Salesforce, part of Office. [13:02](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=782s) **Presenter:** So it's already there. [13:06](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=786s) **Presenter:** And one thing that we haven't seen so far, [13:09](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=789s) **Presenter:** so I showed you a few applications. [13:11](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=791s) **Presenter:** We discussed kind of the growth of this area. [13:14](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=794s) **Presenter:** But one thing that we're missing, [13:15](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=795s) **Presenter:** and I want to make sure that we're all clear about, [13:17](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=797s) **Presenter:** is just how easy it is to build these applications. [13:20](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=800s) **Presenter:** Because that's crucial for you to actually believe [13:23](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=803s) **Presenter:** that people within the business departments [13:25](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=805s) **Presenter:** can actually build this on their own. [13:28](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=808s) **Presenter:** So I'm going to show you an example in a moment. [13:32](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=812s) **Presenter:** Basically, this is a silly example, but we're using Slack in my organization, and Slack has [13:37](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=817s) **Presenter:** this annoying feature where people can mention you in a public channel, and then you're expected [13:44](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=824s) **Presenter:** to reply pretty quickly, which is kind of annoying. [13:47](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=827s) **Presenter:** So what I'm going to do here in this automation is basically, let's see if it works. [13:55](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=835s) **Presenter:** So what I'm going to build is a simple automation that every time somebody mentions me in a [13:59](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=839s) **Presenter:** public channel, it will automatically change my status as if I'm on a call. [14:04](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=844s) **Presenter:** So people will kind of think that I'm not available right now. [14:07](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=847s) **Presenter:** And a few minutes later, it will remove that status so nobody will suspect that I did anything [14:14](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=854s) **Presenter:** wrong. [14:14](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=854s) **Presenter:** Now, this is, of course, a silly example. [14:17](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=857s) **Presenter:** And as I speak, you can see how this is being created. [14:20](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=860s) **Presenter:** This entire video is kind of a couple of minutes. [14:23](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=863s) **Presenter:** This is a pretty sophisticated application, right? [14:26](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=866s) **Presenter:** Just in terms of the number of things that it needs to handle. [14:29](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=869s) **Presenter:** It needs to authenticate to Slack. [14:31](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=871s) **Presenter:** It needs to store a secret because somehow this authentication needs to work. [14:35](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=875s) **Presenter:** It's subscribed to a webhook on the Slack side. [14:38](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=878s) **Presenter:** It needs to support APIs. [14:39](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=879s) **Presenter:** These APIs can change. [14:41](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=881s) **Presenter:** So there's a lot of complexity here. [14:43](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=883s) **Presenter:** There's a delay step because I need to kind of wait between the time that I change the status [14:48](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=888s) **Presenter:** and the first time and the second time. [14:50](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=890s) **Presenter:** So this is a significant piece of software. [14:53](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=893s) **Presenter:** building this in a couple of minutes and this is all drag and drop one of the things that you're [14:58](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=898s) **Presenter:** not seeing and if you're keeping close eye on the video one one thing that you are uh that you won't [15:04](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=904s) **Presenter:** see here is authentication you you didn't see any kind of pop-up window that uh that asked me for [15:10](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=910s) **Presenter:** credentials or anything this just kind of magically happened um and the reason why this is this [15:15](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=915s) **Presenter:** magically happened is because one of the key features of these of these uh platforms is that [15:23](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=923s) **Presenter:** make it very easy to share credentials. They make it very easy to share identities between users. [15:30](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=930s) **Presenter:** And this is important because, and we'll see that in a moment, but basically this is the [15:36](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=936s) **Presenter:** enabler of their growth. If any time you would build such an application, you would need to go [15:42](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=942s) **Presenter:** through approval processes, you would never build anything. But if you can just plug in your own [15:47](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=947s) **Presenter:** identity and continue on, or somebody else's identity because they have the right permissions, [15:53](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=953s) **Presenter:** And so we will dive into that later much deeper. [15:59](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=959s) **Presenter:** Okay. [16:00](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=960s) **Presenter:** So we understand how easy it is. [16:02](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=962s) **Presenter:** I encourage you to play around. [16:04](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=964s) **Presenter:** This is kind of, you'll just see how quickly you can build kind of applications. [16:10](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=970s) **Presenter:** And this is an automation, but basically you can also build mobile apps. [16:14](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=974s) **Presenter:** You can build portals for web apps. [16:16](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=976s) **Presenter:** There are many different options. [16:21](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=981s) **Presenter:** Okay. [16:24](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=984s) **Presenter:** So the reason why now is the time to discuss low code or low code, no code, is that we have a few different factors that all combine in a single time. [16:37](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=997s) **Presenter:** One thing is that the big vendors have a very strong initiative to push this forward. [16:42](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1002s) **Presenter:** You can just imagine kind of thinking, being part of Salesforce or being part of Microsoft and seeing kind of how they can extend the number of developers that are using their platforms from professional developers to business users. [16:56](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1016s) **Presenter:** So the business impact for them is huge. [16:58](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1018s) **Presenter:** The second reason is that this is really necessary. [17:02](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1022s) **Presenter:** So companies need a way to accelerate business and you cannot really rely on just hiring more developers. [17:08](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1028s) **Presenter:** We all know that that is very difficult. [17:12](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1032s) **Presenter:** is that the technology is really there. [17:14](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1034s) **Presenter:** So there were a few attempts in the past [17:16](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1036s) **Presenter:** to build these application generators. [17:18](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1038s) **Presenter:** This one really works. [17:19](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1039s) **Presenter:** This one is able to generate applications [17:21](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1041s) **Presenter:** that are really useful. [17:24](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1044s) **Presenter:** So now we understand why low-code is important [17:26](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1046s) **Presenter:** and why it is important to talk about it now. [17:29](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1049s) **Presenter:** The next thing I want to show you [17:30](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1050s) **Presenter:** before we go into concrete risks [17:32](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1052s) **Presenter:** is how are these things being developed? [17:35](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1055s) **Presenter:** So how does the SDLC translate ### Deep Dive into the Most Common Risks and Mitigations — Part 1 [17:37](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1057s) **Presenter:** to the world of low-code, low-code? [17:41](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1061s) **Presenter:** here's kind of the familiar SDLC [17:44](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1064s) **Presenter:** I won't spend a lot of time here [17:47](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1067s) **Presenter:** this is kind of an attempt to say [17:50](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1070s) **Presenter:** which persona is in charge of each step [17:54](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1074s) **Presenter:** so something gets [17:56](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1076s) **Presenter:** the business thinks about the problem [17:58](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1078s) **Presenter:** it goes to engineering [17:59](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1079s) **Presenter:** they plan a solution [18:00](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1080s) **Presenter:** they implement that solution [18:02](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1082s) **Presenter:** they verify it [18:03](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1083s) **Presenter:** they test it [18:03](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1083s) **Presenter:** deploy, monitor it [18:05](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1085s) **Presenter:** and then manage the software [18:07](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1087s) **Presenter:** as it's live [18:10](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1090s) **Presenter:** updated. Let's try to, and again, this is kind of, this is generic, I'm going to leave it at that. [18:21](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1101s) **Presenter:** The next slide I'm going to show you is basically how does this translate to the world of no code? [18:28](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1108s) **Presenter:** So when you think about it from the perspective of a business user, when a business user is able to [18:35](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1115s) **Presenter:** build their own application, they start with finding an issue. They have some sort of an [18:40](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1120s) **Presenter:** need to solve. And then they just do it. Okay. They don't need to plan. They don't go through [18:47](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1127s) **Presenter:** gates. There's no testing. I mean, there can be testing, but nobody's requiring them to do this [18:53](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1133s) **Presenter:** testing because the business user is the one that is actually doing the entire cycle. [18:58](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1138s) **Presenter:** Now, of course, if you've been working with low code, some organizations are doing this kind of [19:04](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1144s) **Presenter:** very professionally. Some organizations are using the traditional SDLC for low code. But this is [19:10](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1150s) **Presenter:** really not the majority, and this is really not pushed by the platforms. [19:15](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1155s) **Presenter:** One of the hit save to deploy is pretty much the mentality [19:20](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1160s) **Presenter:** in most of these platforms. [19:21](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1161s) **Presenter:** So you build an application, you click save, [19:23](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1163s) **Presenter:** like I just showed you with the Slack automation. [19:28](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1168s) **Presenter:** Once I complete, I hit save, this is in production, this is running. [19:31](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1171s) **Presenter:** That's it. I don't need to do anything else. [19:35](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1175s) **Presenter:** This is at the root of why low-code is successful. [19:40](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1180s) **Presenter:** It just becomes easier when there's not a lot of stakeholders around the table. [19:47](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1187s) **Presenter:** You can iterate very quickly. [19:49](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1189s) **Presenter:** But the gates, of course, are there for a reason. [19:53](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1193s) **Presenter:** So in large enterprises, security is important, compliance is important, privacy, and so on. [19:57](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1197s) **Presenter:** And so these get neglected in most of the cases. [20:02](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1202s) **Presenter:** One last thing I need to cover before I show you concrete risks is why is this your problem? [20:07](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1207s) **Presenter:** Why do you need to think about it? [20:10](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1210s) **Presenter:** that I've been hearing when I'm talking to people about this space is, well, Microsoft [20:14](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1214s) **Presenter:** has introduced this, Salesforce has introduced this. This is their problem. They need to fix it. [20:20](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1220s) **Presenter:** And while this is somewhat true, we need to remember the lessons that we learned from [20:26](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1226s) **Presenter:** the public cloud. So when the public cloud started, people were saying, okay, I'm going to Azure, [20:33](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1233s) **Presenter:** I'm going to AWS. They need to take charge of security, right? But today we understand that [20:40](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1240s) **Presenter:** model, they cannot be in charge of what you build. They are in charge of building secure building [20:46](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1246s) **Presenter:** blocks. But us as the organizations that are actually building applications, we are in charge [20:50](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1250s) **Presenter:** of those applications. And the same thing applies for low code. And this is the part that gets [20:55](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1255s) **Presenter:** neglected. Because usually security teams are not part of the development cycle for low code [21:01](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1261s) **Presenter:** applications. Sometimes it's even not part of the kind of scope of responsibility, which means that [21:07](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1267s) **Presenter:** this gets left out. [21:09](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1269s) **Presenter:** And we'll see in a moment what kind of risk [21:12](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1272s) **Presenter:** occur due to that. [21:15](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1275s) **Presenter:** So [21:17](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1277s) **Presenter:** the [21:17](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1277s) **Presenter:** rest of the talk, we're going to [21:19](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1279s) **Presenter:** talk about the largest risks [21:21](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1281s) **Presenter:** that we see for local and non-code applications. [21:23](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1283s) **Presenter:** And the number one thing [21:26](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1286s) **Presenter:** that you [21:27](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1287s) **Presenter:** need to know before we go into that is [21:29](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1289s) **Presenter:** how did we come up with this list? [21:31](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1291s) **Presenter:** Where is it coming from? [21:33](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1293s) **Presenter:** So we started off [21:37](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1297s) **Presenter:** years ago with the OWASP group for low-code, no-code. [21:42](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1302s) **Presenter:** And since then, we've scanned more than 100,000 applications, something like that, across [21:51](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1311s) **Presenter:** different organizations. [21:52](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1312s) **Presenter:** We've been joined by people from Palo Alto and from Microsoft and other companies as [21:57](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1317s) **Presenter:** well. [21:57](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1317s) **Presenter:** So this is now kind of a cross-company collaboration. [22:00](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1320s) **Presenter:** And I have basically two goals for this talk. [22:05](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1325s) **Presenter:** One is to raise awareness for this issue, and the other is to bring more people to the ORIS group. [22:11](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1331s) **Presenter:** So if you're interested, reach out to me. [22:15](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1335s) **Presenter:** Okay, so here are the top 10. [22:18](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1338s) **Presenter:** And again, this is all based on what we're seeing in actual live environments. [22:25](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1345s) **Presenter:** And we'll go through concrete examples for the top risks. [22:29](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1349s) **Presenter:** By the way, this is kind of an intimate setting. [22:31](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1351s) **Presenter:** So if you have any questions, feel free to kind of raise it during the talk. [22:35](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1355s) **Presenter:** I think it would be nice. [22:37](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1357s) **Presenter:** Okay, let's start with the first risk. [22:40](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1360s) **Presenter:** So imagine that you are in charge of, I don't know, Microsoft or Salesforce or some other platform that is already in large organizations, [22:51](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1371s) **Presenter:** but is trying to push this business development notion or this local development notion. [22:57](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1377s) **Presenter:** The number one thing that will stop you is permissions. [23:01](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1381s) **Presenter:** If any time a business user would like to build an application, [23:05](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1385s) **Presenter:** they need to ask for permissions, nothing is going to happen. [23:08](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1388s) **Presenter:** And so how do you circumvent that issue? [23:10](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1390s) **Presenter:** The way that the platforms work is that basically they allow users [23:17](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1397s) **Presenter:** to connect wherever they want, FTP servers, SQL servers, [23:22](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1402s) **Presenter:** their own identity to Slack or to Teams or whatever, [23:25](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1405s) **Presenter:** and then they copy the refresh token and then they reuse it. [23:31](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1411s) **Presenter:** they allow the users to share it between themselves. [23:33](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1413s) **Presenter:** And this leads to the first risk, which is the counterpersonation. [23:38](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1418s) **Presenter:** Basically, in many cases, applications are being built [23:41](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1421s) **Presenter:** with the maker's identity built into the application, [23:44](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1424s) **Presenter:** which means that every user of the application [23:46](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1426s) **Presenter:** ends up using the maker's identity when they operate. [23:51](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1431s) **Presenter:** And so let's see a real-world example. [23:54](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1434s) **Presenter:** This is from an e-commerce company. [23:57](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1437s) **Presenter:** Basically, they had a problem where the people inside of the company [24:03](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1443s) **Presenter:** that were part of trying to help a customer with a customer case, [24:09](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1449s) **Presenter:** with kind of a ticket, [24:10](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1450s) **Presenter:** they didn't have access to see the history for that customer. [24:13](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1453s) **Presenter:** And so they didn't have the right context. [24:16](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1456s) **Presenter:** Customers were frustrated. [24:18](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1458s) **Presenter:** The customer care team was frustrated. [24:20](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1460s) **Presenter:** So what they wanted to do is build some sort of an application [24:27](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1467s) **Presenter:** in the organization to fetch information related to the cases that they work with. [24:33](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1473s) **Presenter:** Now, of course, you're seeing the challenge here. ### Deep Dive into the Most Common Risks and Mitigations — Part 2 [24:35](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1475s) **Presenter:** Again, getting those permissions, this is a bit difficult. [24:38](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1478s) **Presenter:** So here's the solution that the customer care team has come up with. [24:43](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1483s) **Presenter:** They basically created an application. [24:46](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1486s) **Presenter:** They embedded within the application their own identity, which was an admin on the customer [24:50](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1490s) **Presenter:** database. [24:51](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1491s) **Presenter:** And of course, within the application, they did handle permissions. [24:54](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1494s) **Presenter:** So they did make sure that every user of that application can only see cases that belong to that user. [25:02](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1502s) **Presenter:** But that was handled on the application layer. [25:06](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1506s) **Presenter:** The connection to the database still used an admin connection. [25:10](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1510s) **Presenter:** When you think about it, you can see that the impact was good. [25:14](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1514s) **Presenter:** I mean, this was actually running for a few months. [25:16](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1516s) **Presenter:** So employees are happy. [25:18](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1518s) **Presenter:** Everybody is happy from this situation unless you're in the SOC. [25:23](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1523s) **Presenter:** And so here's what happened. [25:25](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1525s) **Presenter:** From the SOX perspective, there's no application. [25:28](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1528s) **Presenter:** Because this is a shared refresh token, [25:31](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1531s) **Presenter:** this is just a bunch of people across the enterprise [25:34](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1534s) **Presenter:** from multiple machines running multiple queries on their database. [25:38](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1538s) **Presenter:** It looks like scraping, it looks like some kind of an attack. [25:41](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1541s) **Presenter:** So it took them a few weeks to figure out what's going on, [25:45](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1545s) **Presenter:** who's creating those queries, [25:48](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1548s) **Presenter:** and reaching out to finding that this is actually an application, [25:53](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1553s) **Presenter:** finding who built this application, [25:54](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1554s) **Presenter:** And then just imagine this conversation between somebody from the customer care team, somebody from the SOC team discussing this application and the security implications. [26:02](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1562s) **Presenter:** I mean, it's really difficult. [26:04](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1564s) **Presenter:** And so, of course, the problem here is that it doesn't matter who accesses the application, the connection remains the same. [26:17](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1577s) **Presenter:** Now, there are many other kind of, even after this was fixed, there are many other problems there. [26:27](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1587s) **Presenter:** The connections themselves can be implicitly shared. [26:30](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1590s) **Presenter:** And so you're using the application and you gain implicit access to the connection. [26:34](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1594s) **Presenter:** You can just use it, pick it up and use it later on. [26:37](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1597s) **Presenter:** And so this is kind of, the reason why this is the number one problem is that this is very common. [26:44](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1604s) **Presenter:** Very, very common. [26:45](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1605s) **Presenter:** I mean, the number of low-code applications that are using service accounts is really small. [26:50](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1610s) **Presenter:** Most of them use personal accounts either by the maker or by the people that are using them. [26:56](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1616s) **Presenter:** So that was the first one. [26:58](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1618s) **Presenter:** The second one, the second risk is around authorization. [27:02](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1622s) **Presenter:** And now one thing that you could be thinking is, well, authorization is a general application security problem. [27:08](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1628s) **Presenter:** And you're right. [27:09](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1629s) **Presenter:** But the problem, as we've discussed, becomes worse with low code. [27:16](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1636s) **Presenter:** And the reason is credential sharing. [27:19](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1639s) **Presenter:** So as I mentioned, these connections that the applications are creating are actually wrappers around refresh tokens. [27:27](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1647s) **Presenter:** And actually, all of these platforms have some kind of notion of a default environment, [27:34](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1654s) **Presenter:** A place where you develop the applications, a place where everybody has access to the shared resources. [27:40](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1660s) **Presenter:** This place also stores shared connections. [27:43](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1663s) **Presenter:** And in many cases, this is the default. [27:45](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1665s) **Presenter:** So you create a connection. [27:47](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1667s) **Presenter:** It becomes shared with the entire default environment. [27:49](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1669s) **Presenter:** If you're using Microsoft or Zapier or Workato, check out these default environments. [27:54](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1674s) **Presenter:** You'll see in large organizations, I mean, we've seen SQL credentials to production databases, [28:02](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1682s) **Presenter:** people's own accounts to Office or to Outlook [28:05](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1685s) **Presenter:** and they are just there. [28:06](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1686s) **Presenter:** They're waiting for somebody to pick them up and use them. [28:10](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1690s) **Presenter:** And again, keep in mind that there's a reason for that. [28:13](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1693s) **Presenter:** This makes these applications run faster. [28:15](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1695s) **Presenter:** This makes the entire development process run faster. [28:19](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1699s) **Presenter:** Of course, from a security perspective, [28:20](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1700s) **Presenter:** it doesn't make sense at all to share those credentials [28:23](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1703s) **Presenter:** in a way that by sharing the refresh tokens. [28:28](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1708s) **Presenter:** And one more thing that I'm going to say [28:31](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1711s) **Presenter:** of problem, about the [28:33](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1713s) **Presenter:** kind of credential sharing issue, is that [28:35](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1715s) **Presenter:** if you think about it [28:36](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1716s) **Presenter:** in terms of detection, [28:39](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1719s) **Presenter:** how would we detect that [28:41](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1721s) **Presenter:** somebody is using these refresh tokens, [28:43](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1723s) **Presenter:** is sharing those connections from [28:45](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1725s) **Presenter:** the existing infrastructure that we have? [28:47](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1727s) **Presenter:** I mean, from the network security perspective, [28:50](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1730s) **Presenter:** from the application security [28:51](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1731s) **Presenter:** perspective, the logs that you [28:53](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1733s) **Presenter:** already have, none of them [28:55](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1735s) **Presenter:** will tell you that this application even exists. [28:57](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1737s) **Presenter:** Right? [28:58](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1738s) **Presenter:** I mean, every time somebody [29:01](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1741s) **Presenter:** uses the application, they end up going to the database [29:04](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1744s) **Presenter:** or to the [29:05](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1745s) **Presenter:** API with the same refresh [29:07](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1747s) **Presenter:** token from multiple different places. [29:09](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1749s) **Presenter:** The application doesn't exist in terms of [29:11](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1751s) **Presenter:** the current observability [29:13](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1753s) **Presenter:** that you have. And this is the main issue. [29:17](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1757s) **Presenter:** This is more than, this is [29:19](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1759s) **Presenter:** kind of a, this is a crucial [29:21](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1761s) **Presenter:** point because basically this means that [29:23](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1763s) **Presenter:** low code in many cases breaks [29:25](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1765s) **Presenter:** the assumptions that we have around [29:27](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1767s) **Presenter:** permission management. [29:30](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1770s) **Presenter:** one other problem around authorization [29:33](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1773s) **Presenter:** is that we see people basically [29:37](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1777s) **Presenter:** people want to do the right thing [29:39](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1779s) **Presenter:** they want to build an application [29:41](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1781s) **Presenter:** that has a different interface for a user and an admin for example [29:44](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1784s) **Presenter:** but doing that on the connection level [29:47](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1787s) **Presenter:** is difficult [29:48](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1788s) **Presenter:** so they simply do it in the UI level [29:50](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1790s) **Presenter:** on the client side [29:51](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1791s) **Presenter:** and so in many cases [29:54](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1794s) **Presenter:** this is very common in Salesforce for example [29:56](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1796s) **Presenter:** So you build a custom application in Salesforce, and this application has users and admins. [30:01](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1801s) **Presenter:** Both the users and admins see a different kind of UI. [30:06](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1806s) **Presenter:** But if you look behind the scenes at the API, they have the same permissions. [30:09](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1809s) **Presenter:** They can do the same things. [30:12](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1812s) **Presenter:** Okay. [30:13](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1813s) **Presenter:** The next risk is around data leakage. [30:17](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1817s) **Presenter:** And the second thing here is unexpected consequences. [30:21](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1821s) **Presenter:** And just imagine what happens when you have in your organization 70,000 different apps, all of them connecting different kinds of services. [30:30](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1830s) **Presenter:** Things get connected and you're really not sure how. [30:35](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1835s) **Presenter:** It's really difficult to find out what are all of these automations that are moving data between different places. [30:43](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1843s) **Presenter:** So here's an example, and this one is, I mean, every organization that I worked with to find out what's happening with their local platform, this example occurred. [30:57](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1857s) **Presenter:** Basically, it's another way to exfiltrate email outside of your organization. [31:01](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1861s) **Presenter:** So if you're using some sort of a DLP solution to block people from, for example, forwarding email to their personal Gmail, this is very common, right? [31:09](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1869s) **Presenter:** But you do it on the server, on the email server. [31:13](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1873s) **Presenter:** the client or many other things. [31:15](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1875s) **Presenter:** In this example, what people are doing [31:17](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1877s) **Presenter:** is that they're actually [31:19](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1879s) **Presenter:** copying the data. So for every time [31:21](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1881s) **Presenter:** they get an email, they copy the content [31:23](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1883s) **Presenter:** of the email and they paste it [31:25](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1885s) **Presenter:** in their own personal box. [31:28](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1888s) **Presenter:** Again, automated. [31:29](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1889s) **Presenter:** And so you won't find it in the email [31:31](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1891s) **Presenter:** logs, DLP solutions won't catch [31:33](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1893s) **Presenter:** it for you. This is, again, ### Deep Dive into the Most Common Risks and Mitigations — Part 3 [31:36](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1896s) **Presenter:** very, very, very common across different [31:37](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1897s) **Presenter:** organizations. [31:40](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1900s) **Presenter:** Here's [31:40](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1900s) **Presenter:** one funny example [31:43](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1903s) **Presenter:** one of the earliest customers I've worked with, [31:48](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1908s) **Presenter:** we kind of scanned their Wokato environment, [31:50](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1910s) **Presenter:** and we found this kind of automation [31:53](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1913s) **Presenter:** that was syncing an account for a vendor. [31:57](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1917s) **Presenter:** The vendor had their own personal Gmail account [32:00](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1920s) **Presenter:** and their corporate account, [32:01](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1921s) **Presenter:** and they were forwarding email from their corporate account [32:04](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1924s) **Presenter:** to their Gmail account. [32:05](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1925s) **Presenter:** And this sync was still up and running [32:07](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1927s) **Presenter:** three years after the vendor was left the organization. [32:12](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1932s) **Presenter:** here's another example [32:13](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1933s) **Presenter:** it's very easy to create [32:16](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1936s) **Presenter:** disruptions with this kind of [32:18](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1938s) **Presenter:** technology [32:18](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1938s) **Presenter:** this is a simple example [32:22](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1942s) **Presenter:** where basically it builds [32:24](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1944s) **Presenter:** a ransomware [32:27](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1947s) **Presenter:** completely with [32:28](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1948s) **Presenter:** low code so it's pretty [32:30](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1950s) **Presenter:** easy, I go to a SharePoint site, I list [32:32](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1952s) **Presenter:** all of the files, I encrypt them [32:34](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1954s) **Presenter:** with a handy encrypt function that is provided [32:36](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1956s) **Presenter:** by the platform and then I replace [32:40](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1960s) **Presenter:** Actually, if you're interested in that perspective, in the attacker's perspective on low-code, no-code, there was a whole bunch of information we put out there. [32:48](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1968s) **Presenter:** There were a couple of talks at DEFCON. [32:50](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1970s) **Presenter:** So look it up online. [32:53](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1973s) **Presenter:** There's a lot of information. [32:57](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1977s) **Presenter:** Next up, authentication and authorization. [33:01](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1981s) **Presenter:** When you create those applications, the reason why they are useful is because they connect. [33:10](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1990s) **Presenter:** corporate data sets. [33:11](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1991s) **Presenter:** When you do these connections, you need to make choices. [33:14](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1994s) **Presenter:** You need to decide when you connect to an FTP server, [33:17](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=1997s) **Presenter:** you need to decide whether you're using FTP or FTPS. [33:20](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2000s) **Presenter:** When you plug into Salesforce, [33:23](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2003s) **Presenter:** you need to decide whether you're going to a sandbox environment or not. [33:25](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2005s) **Presenter:** There are a lot of these choices that are around creating secure connections. [33:30](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2010s) **Presenter:** And now, who's making those choices? [33:32](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2012s) **Presenter:** Again, business users. [33:33](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2013s) **Presenter:** So, of course, they don't know what are the implications of those choices, [33:37](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2017s) **Presenter:** which means that we see things we thought we have solved a long time ago, [33:47](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2027s) **Presenter:** like FTP rather than FTPS, within large organizations. [33:50](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2030s) **Presenter:** Again, this is something that people are saying today. [33:52](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2032s) **Presenter:** And so, of course, this is not really something we can expect from business users. [33:56](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2036s) **Presenter:** It's not their job to do it. [33:58](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2038s) **Presenter:** It's our job to kind of make it easy for them to make the right choice. [34:05](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2045s) **Presenter:** the next problem that we're seeing is security misconfiguration now again this is something that [34:11](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2051s) **Presenter:** is common to every platform once it starts to grow i mean when the platform is small it has a [34:18](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2058s) **Presenter:** very limited amount of features and it's difficult to um and most of them are kind of [34:23](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2063s) **Presenter:** kind try to be secure by design but when you grow as a platform for example when you want to create [34:29](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2069s) **Presenter:** an application, when the platform wants to offer an application that is available for [34:34](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2074s) **Presenter:** anonymous users without logins, so you have to have an API that exposes information to [34:39](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2079s) **Presenter:** anonymous users. [34:39](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2079s) **Presenter:** That's a fine, that's a valid use case. [34:42](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2082s) **Presenter:** But now we need to choose which APIs are exposed to anonymous users and which are not. [34:48](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2088s) **Presenter:** And of course, as we know, when you're making these choices, you're going to make wrong [34:53](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2093s) **Presenter:** decisions. [34:54](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2094s) **Presenter:** And so we're seeing a lot of problems that are very similar to the Open S3 bucket that [34:59](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2099s) **Presenter:** We as an industry have been trying to tackle for a few years now. [35:02](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2102s) **Presenter:** And this again pop up again here. [35:05](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2105s) **Presenter:** So let me show you a concrete example. [35:08](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2108s) **Presenter:** Microsoft has one of the types of applications that they expose. [35:13](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2113s) **Presenter:** It's called Portal App. [35:14](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2114s) **Presenter:** This is an application that, again, that is exposed to anonymous users. [35:18](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2118s) **Presenter:** So for example, if you want to build a vendor portal for your vendors to kind of sign up and then log in and fetch information about their relationship with you, [35:29](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2129s) **Presenter:** can use this portal app in order to facilitate that. [35:35](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2135s) **Presenter:** This portal app exposes an API for anonymous users. [35:39](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2139s) **Presenter:** And again, this makes sense, right? [35:43](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2143s) **Presenter:** Not everybody has a login. [35:45](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2145s) **Presenter:** The problem here was that the default setting for this portal [35:49](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2149s) **Presenter:** was exposing the entire API of the portal, [35:52](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2152s) **Presenter:** so all of the data sets, to anonymous users. [35:54](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2154s) **Presenter:** And this was the default for a few years. [35:56](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2156s) **Presenter:** This was discovered last year, so you can see the result. [36:01](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2161s) **Presenter:** And Microsoft was actually pretty quick in changing the default, which is nice. [36:06](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2166s) **Presenter:** But it doesn't prevent people from moving from a secure default to an insecure situation. [36:12](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2172s) **Presenter:** So here's what we did. [36:15](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2175s) **Presenter:** All of these portals are under the same domain, so it's very easy to enumerate. [36:22](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2182s) **Presenter:** These are simple subdomain enumeration, and you can find all of those portals. [36:26](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2186s) **Presenter:** And then the way that you access the anonymous data is just by going to this OData endpoint. [36:33](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2193s) **Presenter:** Again, pretty easy. [36:34](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2194s) **Presenter:** So let's see how many of them we can find today. [36:38](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2198s) **Presenter:** Here's an example of how this looks like. [36:41](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2201s) **Presenter:** You can see I'm going to this OData endpoint. [36:45](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2205s) **Presenter:** By the way, this example is from a real portal that we found for a large bank. [36:51](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2211s) **Presenter:** And you can see that there are three different entities here. [36:54](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2214s) **Presenter:** Default doesn't have anything really interesting. [36:57](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2217s) **Presenter:** Entity forms, it is just a way to save forms. [37:00](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2220s) **Presenter:** But you're also seeing the global variables entity. [37:04](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2224s) **Presenter:** Interesting. [37:05](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2225s) **Presenter:** Here's what the global variables entity has. [37:09](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2229s) **Presenter:** Hardcoded secrets to the Azure deployment for the bank. [37:14](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2234s) **Presenter:** This is one example, but we found PII. [37:18](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2238s) **Presenter:** We found signed contracts with customers. [37:22](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2242s) **Presenter:** And again, because this is in a single domain, it's waiting for you to kind of reach out and do it. [37:30](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2250s) **Presenter:** And this is still the situation today. [37:33](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2253s) **Presenter:** So from us playing around with this, we found something like 50,000 different portals that are available today. [37:43](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2263s) **Presenter:** And some of them still have these issues. [37:47](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2267s) **Presenter:** Again, this is not, I mean, Microsoft does have some of the faults here to make it, they [37:53](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2273s) **Presenter:** need to make it easier, but actually, I mean, users need to make the right choice. [37:57](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2277s) **Presenter:** There is a valid use case here, and the people that are making this choice is usually business [38:01](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2281s) **Presenter:** users. [38:03](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2283s) **Presenter:** Let's see another one. [38:06](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2286s) **Presenter:** The next one is about injection handling failures. [38:10](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2290s) **Presenter:** So here's an automation we saw kind of a few months ago. [38:16](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2296s) **Presenter:** A user created a way, basically an automation that goes through an RSS feed. [38:23](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2303s) **Presenter:** And every time something comes from that RSS feed, they download the article and they push it to a SQL server. ### Deep Dive into the Most Common Risks and Mitigations — Part 4 [38:30](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2310s) **Presenter:** And the way that they do it is with kind of a SQL query, like an arbitrary query. [38:37](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2317s) **Presenter:** So, of course, this is a pass to injection. [38:40](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2320s) **Presenter:** This is very similar to injection surface in serverless functions, [38:45](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2325s) **Presenter:** where you have these weird inputs and outputs that can be files and all sorts of other things. [38:51](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2331s) **Presenter:** This is, again, very common within these local applications. [38:54](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2334s) **Presenter:** And, of course, business users don't really know what to do with injection. [39:01](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2341s) **Presenter:** Now, one of the things that the platforms are saying, and if you read kind of their marketing material, [39:06](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2346s) **Presenter:** they'll tell you that they fixed SQL injection. [39:10](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2350s) **Presenter:** fixed injection in general and everything is all right. [39:13](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2353s) **Presenter:** But if you, and I mean, part of that is true, right? [39:15](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2355s) **Presenter:** They have text fields and they sanitize the input there. [39:19](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2359s) **Presenter:** But when you sanitize the input, you need to know where this data is going. [39:23](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2363s) **Presenter:** Is it going to be read as JSON? [39:25](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2365s) **Presenter:** Is it going to be plugged into a SQL server? [39:27](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2367s) **Presenter:** You can't really sanitize from everything without knowing what's going to be the next step. [39:31](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2371s) **Presenter:** Again, this is our responsibility. [39:36](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2376s) **Presenter:** Here's another one, which is again, kind of pretty obvious. [39:41](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2381s) **Presenter:** Low code is only useful because you can drag and drop ready-made features like ready-made [39:48](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2388s) **Presenter:** widgets, ready-made connectors. [39:51](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2391s) **Presenter:** These are part of marketplace. [39:53](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2393s) **Presenter:** Some of them are provided by a vendor, others are provided by open source. [39:57](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2397s) **Presenter:** And so your users will go through the marketplace or will just find the right blog pointing [40:04](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2404s) **Presenter:** GitHub repo, they'll upload something [40:06](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2406s) **Presenter:** and that's it. In Microsoft you can [40:08](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2408s) **Presenter:** upload the DLL, in Zapier [40:10](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2410s) **Presenter:** you can run custom code. [40:12](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2412s) **Presenter:** These are things that are plugged directly into [40:14](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2414s) **Presenter:** the platform, there's no way to inventory [40:16](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2416s) **Presenter:** them, there's no way to know that this is actually happening [40:18](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2418s) **Presenter:** and so of course there's a problem [40:20](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2420s) **Presenter:** here with dependencies [40:22](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2422s) **Presenter:** and with kind of the same [40:25](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2425s) **Presenter:** we've done a lot as an [40:26](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2426s) **Presenter:** industry to be better [40:28](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2428s) **Presenter:** with open source and [40:30](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2430s) **Presenter:** mapping out our dependencies, we'll still [40:34](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2434s) **Presenter:** we haven't really started. [40:39](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2439s) **Presenter:** The next risk is around data and secret management. [40:43](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2443s) **Presenter:** So in many cases, we see basically these applications [40:47](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2447s) **Presenter:** are handling sensitive data. [40:48](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2448s) **Presenter:** And of course, people don't know how to handle this correctly. [40:51](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2451s) **Presenter:** So let me, so you can see kind of a concrete example here, [40:56](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2456s) **Presenter:** but let me tell you the story around it. [40:58](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2458s) **Presenter:** So this is a large IT company. [41:00](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2460s) **Presenter:** and the HR team basically created a giveaway campaign [41:04](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2464s) **Presenter:** where you can donate money to charity. [41:06](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2466s) **Presenter:** So here's what they did. [41:07](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2467s) **Presenter:** They built an application. [41:08](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2468s) **Presenter:** The application asked you, [41:11](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2471s) **Presenter:** how much do you want to donate to which charity? [41:14](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2474s) **Presenter:** And please plug in your credit card. [41:16](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2476s) **Presenter:** Of course, the credit card was collected, [41:19](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2479s) **Presenter:** stored in a database. [41:20](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2480s) **Presenter:** The database is stored unencrypted. [41:23](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2483s) **Presenter:** The database was part of the default environment, [41:25](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2485s) **Presenter:** which means it's exposed to the entire organization. [41:28](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2488s) **Presenter:** So this is pretty cool. [41:30](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2490s) **Presenter:** From the perspective of, I mean, how advanced this HR team is, [41:35](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2495s) **Presenter:** but from the security perspective, it's kind of problematic. [41:41](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2501s) **Presenter:** Here's another one, and this one is kind of larger. [41:46](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2506s) **Presenter:** Because most security teams and most IT teams are not aware of these applications, [41:53](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2513s) **Presenter:** there's really a problem here with asset management. [41:56](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2516s) **Presenter:** So you saw how easy it is to create those applications. [42:01](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2521s) **Presenter:** It's even easier to maintain them because you don't really need to do anything. [42:05](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2525s) **Presenter:** You don't need to update. [42:06](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2526s) **Presenter:** You don't need to do anything on your own. [42:09](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2529s) **Presenter:** And so that's why you have the graph that you saw at the beginning of this talk. [42:14](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2534s) **Presenter:** Because, well, it's very easy to create application. [42:17](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2537s) **Presenter:** A lot more people can create those applications. [42:19](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2539s) **Presenter:** Of course, you'll have a lot of applications. [42:21](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2541s) **Presenter:** And some of these applications, not all of them, [42:23](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2543s) **Presenter:** but some of them will be used by a lot of business users without IT being involved. [42:27](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2547s) **Presenter:** And it's really difficult to find those critical applications that you need to put under the IT umbrella. [42:33](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2553s) **Presenter:** There's a lot of issues here around applications that are left unused [42:39](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2559s) **Presenter:** or applications that are actually being used by the organization. [42:42](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2562s) **Presenter:** And then their maker leaves the org and the application is offened and nobody finds it. [42:47](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2567s) **Presenter:** So this is another kind of common thing. [42:49](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2569s) **Presenter:** one of the first things that customers do, that organizations do when they start to address this [42:55](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2575s) **Presenter:** space is figure out just how many of the applications can be purged. In many cases, [43:00](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2580s) **Presenter:** it's a lot of them. And the last one is around security logging. So you would expect applications [43:09](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2589s) **Presenter:** that are being created in a platform that kind of generates these applications to have all of [43:14](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2594s) **Presenter:** the logs that you want, right? Everything can be plugged in. That expectation would be way off. [43:20](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2600s) **Presenter:** The logs for most of these platforms are almost non-existent. And where you'll find logs, [43:29](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2609s) **Presenter:** you'll typically find secrets and data that is being written into those logs. As an example, [43:35](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2615s) **Presenter:** if you're using an automation platform like Zapier or Workator or Power Automate, [43:41](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2621s) **Presenter:** the actual content that goes through that automation is being written to logs. [43:46](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2626s) **Presenter:** And so if you're handling credit cards, they are there on the logs. [43:51](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2631s) **Presenter:** This is, again, this is a place where the platforms themselves need to do a lot of, [43:56](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2636s) **Presenter:** need to have kind of, need to go to a better place in terms of their maturity. [44:01](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2641s) **Presenter:** This is a problem if you want to do any security login and monitoring. [44:06](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2646s) **Presenter:** Okay. [44:07](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2647s) **Presenter:** So we've seen the top risks. [44:12](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2652s) **Presenter:** So you know what? [44:14](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2654s) **Presenter:** I have a slide for summary, so why not? [44:17](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2657s) **Presenter:** The first thing that we've seen, and this is the most important, crucial part here, [44:22](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2662s) **Presenter:** is that low-code is growing rapidly, and it's growing whether you'd like it or not. [44:26](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2666s) **Presenter:** This is the reality. [44:28](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2668s) **Presenter:** So this is probably in most organizations today. [44:33](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2673s) **Presenter:** In most of the organizations that I got to work with, we start off with finding that they have one platform, [44:41](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2681s) **Presenter:** find that they have like six or seven that are already there in their organization. [44:45](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2685s) **Presenter:** There's no real SDLC here, which causes a lot of these issues. [44:48](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2688s) **Presenter:** And you've also seen the OWASP top 10. [44:51](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2691s) **Presenter:** I encourage you to check us out online. [44:55](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2695s) **Presenter:** There's a lot of other information. [44:57](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2697s) **Presenter:** And we're also always looking for collaborators. [45:00](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2700s) **Presenter:** I'll leave you off with these slides, which are kind of the opportunities. [45:05](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2705s) **Presenter:** Because this is a new space, there's a lot of opportunity for evangelism. [45:09](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2709s) **Presenter:** We see organizations that are kind of creating security frameworks or trying to figure out how does SDLC work for low-code, no-code in their organization. [45:20](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2720s) **Presenter:** There's a lot of opportunity here to create those approved use cases with users and kind of guide business users in the right direction. [45:28](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2728s) **Presenter:** And the last thing I'll say here is that even though this seems like a giant risk for us as security professionals, this is also a giant opportunity. [45:40](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2740s) **Presenter:** Security awareness has always been difficult, and getting the business to buy into security has always been difficult. [45:46](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2746s) **Presenter:** But now business users need us. [45:50](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2750s) **Presenter:** They need us to guide them in the right direction. [45:52](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2752s) **Presenter:** And if we'll be there with them in this journey, it will be much easier for us to get their buy in return. [46:01](https://www.youtube.com/watch?v=Skr4Yj3s8ms&t=2761s) **Presenter:** Thank you very much. ## Slide text Source: [published deck manifest](https://media.mbgsec.com/decks/2022-10-28-LASCON_No_Code_Risk_What_Happens_When_We_Leave_No_Code_up_for_Grabs/39ea6d90/deck.json). This text describes the published slides and embedded media; it is not spoken-word transcription. ### Slide 1 No Code No Risk? — What Happens When We Leave No Code up for Grabs — Michael Bargury @ Zenity — slide 1 of 55 ### Slide 2 About me — CTO and co-founder @ Zenity — Ex MSFT cloud security — slide 2 of 55 ### Slide 3 Outline — How pervasive is it? — Low Code / No Code growth and evolution — slide 3 of 55 ### Slide 4 Business-Led Development Is Here — slide 4 of 55 ### Slide 5 Exponential Growth in Business Development — slide 5 of 55 ### Slide 6 The Low-Code/No-Code Evolution: — How did we get here? — slide 6 of 55 ### Slide 7 Business Needs — ⋙ — IT Capacity — slide 7 of 55 ### Slide 8 If it sounds familiar, its because it is — Tech evolution — slide 8 of 55 ### Slide 9 Build everything — If this than that automation — Integrations — slide 9 of 55 ### Slide 10 Available in every major enterprise — slide 10 of 55 ### Slide 11 Build Business Apps Faster — How low code / no node accelerates development: — Ease of use lowers barrier to entry — slide 11 of 55 ### Slide 12 COVID health check app by Microsoft — https://aka.ms/healthcheck — slide 12 of 55 ### Slide 13 Order-to-cash automation by Slack — https://www.workato.com/the-connector/how-slack-automated-order-to-cash/ — slide 13 of 55 ### Slide 14 https://www.microsoft.com/insidetrack/blog/how-citizen-developers-modernized-microsoft-product-launches/ — “… A Business Operations program manager, and her team, were searching for a way to optimize the launch process for the 150 employees who ran product launches across the com — slide 14 of 55 ### Slide 15 “With Dynamics, …, we also launched this very powerful platform, the Power Platform -- … which acts as the extensibility framework for Microsoft Graph, extensibility framework for Dynamics, as well as Microsoft 365, and embeddable by every SaaS ISV.“ — Satya Nadella, Microsoft Bu — slide 15 of 55 ### Slide 16 “Anyone can be a developer, completely transforming how your business operates” — “… we need to empower citizen developers with tools that are low-code/no-code tools so that they can build out these applications …. In fact, there are already 2.5 million citizen developers using P — slide 16 of 55 ### Slide 17 “By 2025, 70% of new applications deployed for the enterprise will use low-code or no-code tools, up from less than 25% in 2020.” — “With Power Platform, we have the leading business process automation and productivity suite for domain experts in every industry, with 20 million m — slide 17 of 55 ### Slide 18 Demo of a Zapier automation that responds to a public Slack mention by starting a call and sending an email reminder — slide 18 of 55 - Youtube: [defcon30 Ohh sorry I'm on another call](https://www.youtube.com/watch?v=5naPxs0fEJc) ### Slide 19 Big vendors have a strong incentive to empower business users — Companies are lacking IT resources and need a solution for accelerated development — The tech is already there – business users are actually using it — slide 19 of 55 ### Slide 20 No Code No SDLC? — slide 20 of 55 ### Slide 21 Software Development Lifecycle — Envision — Plan — slide 21 of 55 ### Slide 22 Software Development Lifecycle — Envision — Plan — slide 22 of 55 ### Slide 23 No Code SDLC? — Envision — Plan — slide 23 of 55 ### Slide 24 The Shared Responsibility Model — slide 24 of 55 ### Slide 25 OWASP Top 10 Low-Code/No-Code Security Risks — slide 25 of 55 ### Slide 26 Top 10 Security Risks — https://owasp.org/www-project-top-10-low-code-no-code-security-risks — slide 26 of 55 ### Slide 27 LCNC-SEC-01: Account Impersonation — LCNC-SEC-02: Authorization Misuse — LCNC-SEC-03: Data Leakage and Unexpected Consequences — slide 27 of 55 ### Slide 28 Low-code/no-code applications can be embedded with user identities which are used implicitly by any application user. This creates a direct path towards Privilege Escalation, allows an attacker to hide behind another user's identity, and circumvents traditional security controls. — slide 28 of 55 ### Slide 29 The Customer Care team at a large eCommerce company wanted to improve customer service. — Goal — : improve customer service — slide 29 of 55 ### Slide 30 Customer care app — Customer DB — Admin — slide 30 of 55 ### Slide 31 Impact: — Employees are happy — Customers are happy — slide 31 of 55 ### Slide 32 Abnormal activity detected: — Customer DB is being scraped? — Lots of queries — slide 32 of 55 ### Slide 33 Admin — User — App — slide 33 of 55 ### Slide 34 Service connections are first class objects in most low-code/no-code platforms. This means they can be shared between applications, with other users or with entire organizations. — LCNC-SEC-02: Authorization Misuse — slide 34 of 55 ### Slide 35 Credential Sharing as a Service — slide 35 of 55 ### Slide 36 Authorization as front-end logic — /user — API — slide 36 of 55 ### Slide 37 Low-code/no-code applications often sync data or trigger operations across multiple systems, which creates a path for data to find its way outside the organizational boundary. This means that operations in one system can have unexpected consequences in another. — LCNC-SEC-03: Dat — slide 37 of 55 ### Slide 38 Data is being copied between two separate services using two separate identities – — existing defense mechanisms fail — LCNC-SEC-03: Data Leakage and Unexpected Consequences — slide 38 of 55 ### Slide 39 If — Then — LCNC-SEC-03: Data Leakage and Unexpected Consequences — slide 39 of 55 ### Slide 40 Low-code/no-code applications typically connect to business-critical data via connections set up by business users, which can often result in insecure communication. — LCNC-SEC-04: Authentication and Secure Communication Failures — slide 40 of 55 ### Slide 41 Misconfigurations can often result in anonymous user access to sensitive data or operations, unprotected public endpoints, unprotected secrets and oversharing. — LCNC-SEC-05: Security Misconfiguration — slide 41 of 55 ### Slide 42 LCNC-SEC-05: Security Misconfiguration — slide 42 of 55 ### Slide 43 “An open protocol to allow the creation and consumption of queryable and interoperable RESTful APIs in a simple and standard way.” — Power portals can be configured to provide access to SQL tables through ODATA using a specific URL: — portal.powerappsportals.com/_odata — slide 43 of 55 ### Slide 44 Power portals can be configured to provide access to SQL tables through ODATA using a specific URL: — portal.powerappsportals.com/_odata — zenity.io/blog/the-microsoft-power-apps-portal-data-leak-revisited-are-you-safe-now/ — slide 44 of 55 ### Slide 45 /_odata/globalvariables: — Nothing to see here — slide 45 of 55 ### Slide 46 Low-code/no-code applications ingest user provided data in multiple ways, including direct input or retrieving user provided content from various services. Such data can contain malicious payloads that may introduce risk to the application. — App — Query — slide 46 of 55 ### Slide 47 Low-code/no-code applications rely heavily on ready-made components out of the marketplace, the web or custom connectors built by developers. These component are often unmanaged, lack visibility and expose applications to supply chain-based risks. — 3 — rd — slide 47 of 55 ### Slide 48 Low-code/no-code applications often store data or secrets as part of their "code" or on managed databases offered by the platform, which needs to be properly stored in compliance with regulation and security requirements. — App — Store in plaintext — slide 48 of 55 ### Slide 49 HR team at a large IT company kicked off a Giveaway campaign — App let’s you choose your donation, charity and plug in your credit card — Cards are stored in plaintext on an environment available to everyone, including tenant guests — slide 49 of 55 ### Slide 50 Low-code/no-code application are easy to create and have relatively low maintenance costs, which makes them prone to abandonment, while still remaining active. Furthermore, internal applications can gain popularity rapidly, without addressing business continuity concerns. — App — slide 50 of 55 ### Slide 51 Low-code/no-code applications often lack a comprehensive audit trail, produce none or insufficient logs, and fail to scrub sensitive data from logs. — LCNC-SEC-10: Security Logging and Monitoring Failures — slide 51 of 55 ### Slide 52 Summary section divider — slide 52 of 55 ### Slide 53 What have we seen — Low Code / No Code is growing rapidly — Probably already in your org — slide 53 of 55 ### Slide 54 Opportunities - Champion Low Code / No Code AppSec in your org — Create a Low Code / No Code Security Framework — No Code SDLC — slide 54 of 55 ### Slide 55 No Code No Risk? — What Happens When We Leave No Code up for Grabs — Michael Bargury @ Zenity — slide 55 of 55