Abstract
Discover what extensive research has revealed on the security of low-code/no-code applications based on scanning over 100,000 applications across hundreds of enterprise environments. Join guest speaker Michael Bargury, Co-Founder and CTO of Zenity, as he introduces the new OWASP Top 10 list, demonstrates how most applications get an identity, and shares a wide range of security issues and their backstories found in real-world environments.
Transcript
AI generated from recording.
Introduction and Context; Low‑Code/No‑Code Landscape; Growth and Pervasiveness; Low‑Code SDLC Overview
00:00 Presenter: Happy New Year to everyone. I’m your host, Kasey Zirkus, Content Strategist for RSA Conference. Thank you so much for joining us today. Our guest is Michael Bargery and he will be talking about OWASP Top 10 Risks for Low-code, No-code. Just so that you know, a reminder to our audience, all participants will be in listen-only mode. Michael will be taking questions, so if you have a question, please submit it through the Q&A feature on your screen.
00:30 Presenter: Please note that this is not a live chat.
00:33 Presenter: It’s just an inbound question that goes directly to Michael.
00:37 Presenter: As a reminder, this webcast is being recorded, and following the webcast, you’ll receive an email containing the link to the video replay.
00:44 Presenter: The replay, along with the slides, will be posted on rsaconference.com.
00:49 Presenter: Also, I’m pleased to remind you that as part of our RSAC 365 Cybersecurity Learning Program, we accept submissions on any topic year-round.
01:00 Presenter: expertise on a webcast, podcast, seminar, or blog by visiting rsaconference.com forward slash
01:06 Presenter: become a contributor. I now invite Michael to introduce himself and dive right into today’s
01:12 Presenter: topic. Michael, over to you. Thank you, Casey. Hi, everyone. Excited to be here. My name is Michael
01:21 Presenter: and we’ll be spending the next hour or so together. So let me kind of start with a
01:28 Presenter: brief introduction. This talk is going to be interesting because the subject of this talk,
01:34 Presenter: focusing on low-code, low-code, is really an underexplored area with security. I’ve been in
01:40 Presenter: this space for three to four years now, working around the intersection of low-code and security.
01:47 Presenter: About two years ago, I co-founded Xenity, which is a company focused on this space, and a lot of my
01:53 Presenter: observations come from this company.
01:55 Presenter: I’ve spent several years at Microsoft as part of the CTO office for
02:00 Presenter: Azure security where I spent time working with our top customers to try and
02:07 Presenter: address large problems like IoT, cloud, and confidential computing.
02:13 Presenter: I also lead an OWASP group that is dedicated to low code, no code.
02:18 Presenter: And this OWASP group is far bigger than myself.
02:22 Presenter: as we move forward, this talk is going to be focused
02:26 Presenter: on the main thing that we’ve been working on,
02:28 Presenter: which is finding and categorizing
02:31 Presenter: those top 10 risks for low code.
02:33 Presenter: I also write about low code, no code security
02:36 Presenter: and dark reading.
02:37 Presenter: If there’s anything you’re interested in this talk,
02:40 Presenter: if you find this kind of thing resonating with you,
02:43 Presenter: please reach out.
02:45 Presenter: We are always looking for collaborators.
02:50 Presenter: So here’s what we’re going to do today.
02:53 Presenter: We’re gonna start with understanding
02:55 Presenter: just how pervasive low code, no code is.
02:58 Presenter: So how wide is it being used across the industry?
03:01 Presenter: We’re going to see how low code, no code grows
03:04 Presenter: or how did it grow?
03:06 Presenter: How did we get to where we are today?
03:09 Presenter: Later on, we’re going to dive into the low code SDLC
03:12 Presenter: and understand fundamentally what are the challenges
03:17 Presenter: and after that we dive into the Diorus top 10,
03:20 Presenter: understand with concrete real world issues,
03:24 Presenter: why real world examples,
03:26 Presenter: why are these things so important?
03:31 Presenter: And so without further ado,
03:34 Presenter: I’m going to start with how pervasive low code, no code is.
03:38 Presenter: And the next slide that I’m going to show
03:41 Presenter: is probably the most important slide in the entire talk.
03:44 Presenter: And that is because this slide is going to show us
03:50 Presenter: how fast low code, no code grows
03:54 Presenter: and how significantly different it is
03:56 Presenter: in terms of scale from what we’ve been used to.
04:00 Presenter: This chart right here shows you anonymized statistics
04:03 Presenter: that represent a single Fortune 500 customer
04:07 Presenter: and then a single Fortune 500 company
04:10 Presenter: and the number of applications,
04:12 Presenter: low-code, no-code applications
04:14 Presenter: that they have over multiple years.
04:17 Presenter: And you can see the exponential growth
04:19 Presenter: in the number of applications.
04:21 Presenter: Now, of course, the definition of application
04:23 Presenter: is really important here, right?
04:25 Presenter: Application could be something very large,
04:27 Presenter: but it could also be a micro-application
04:29 Presenter: doing a single kind of a process.
04:32 Presenter: And here you get a whole bunch of those.
04:35 Presenter: So with those large numbers,
04:36 Presenter: some of these applications would be very small
04:43 Presenter: and other applications would be huge.
04:45 Presenter: This also means that these are not applications
04:48 Presenter: that are only getting built by IT.
04:51 Presenter: With such large numbers, most of these applications
04:55 Presenter: are actually being built by business teams.
04:57 Presenter: And this is why this matters.
04:59 Presenter: It matters both in terms of the number of applications
05:02 Presenter: that are being built.
05:03 Presenter: Of course, manual reviews are out of the question.
05:06 Presenter: of numbers, but it’s also important in terms of who’s building those applications.
05:11 Presenter: This chart right here is the reason why this is so important for us to tackle this.
05:16 Presenter: Because as the sooner we get on bringing low code,
05:21 Presenter: no code under the security umbrella, the better we’ll be left off.
05:28 Presenter: So now that we understand why low code, no code, or why now that we have kind of a
05:32 Presenter: feeling of why low code, no code is something that we need to focus on.
05:36 Presenter: what low-code and no-code is exactly,
05:38 Presenter: and how do we get to where we are?
05:41 Presenter: So this slide tries to capture basically
05:44 Presenter: the reason behind low-code and no-code.
05:46 Presenter: Why does low-code and no-code exist?
05:48 Presenter: Of course, there’s the perennial problem
05:50 Presenter: of resource shortage, right?
05:54 Presenter: The business needs much more than IT is able to provide,
05:57 Presenter: and we’ve all felt this ourselves,
Risk Framework Introduction
05:59 Presenter: and we see other people feeling it
06:01 Presenter: throughout the business all of the time.
06:03 Presenter: Now, when we see that these kind of, as a business user, of course, the frustration of waiting for IT is something that people are used to.
06:14 Presenter: And people have been trying to find ways to get business users to build their own things, to solve their own problems for a long time, right?
06:25 Presenter: If this sounds familiar, the entire concept of empowering business users, it’s because it is.
06:32 Presenter: We’ve been trying throughout the history to put more power in the hands of business users for a long time now,
06:39 Presenter: from application generators to Visual Basic to Excel to things that are about helping business users address their own needs.
06:49 Presenter: And low-code, no-code is, of course, just another step in this trend of IT decentralization,
06:56 Presenter: providing the ability for business users to solve their own problems.
06:59 Presenter: Now, of course, with these kind of technologies, we also know what happened with them on the
07:05 Presenter: other side.
07:06 Presenter: So we also know that everything that we put out there for business users to use can also
07:11 Presenter: be abused by malicious intent.
07:14 Presenter: And so here are a few examples of what people are building
07:20 Presenter: with low code, no code.
07:21 Presenter: So it could be if small automation.
07:26 Presenter: So for example, every time I get an email,
07:28 Presenter: do something with that email.
07:30 Presenter: So for example, look for specific emails
07:32 Presenter: and store their attachments somewhere.
07:34 Presenter: It could be integration.
07:36 Presenter: So you could have a business application
07:37 Presenter: or business integration team within IT
07:39 Presenter: that is connecting together the various parts of the enterprise.
07:44 Presenter: It could be business applications that are used for internal or external operations.
07:48 Presenter: It could be entire products, entire products built with no-code, no-code, mobile apps.
07:52 Presenter: You’re seeing on screen a bunch of examples,
07:55 Presenter: but shortly I will share a few concrete examples from organizations that we’ve been working with.
08:01 Presenter: By the way, I’m getting a question.
08:03 Presenter: I’m seeing a question in the Q&A asking about the numbers that we saw earlier
08:09 Presenter: everything that you’re going to see in these slides today
08:14 Presenter: is coming from anonymized statistics
08:16 Presenter: that were either shared by organizations
08:18 Presenter: that are part of the OWASP group,
08:20 Presenter: or that were shared,
08:22 Presenter: or they are part of kind of applications
08:25 Presenter: that they have looked at.
08:26 Presenter: So together with the entire OWASP group,
08:30 Presenter: this is a culmination of scanning
08:32 Presenter: more than 100,000 different applications
08:34 Presenter: across multiple organizations.
08:39 Presenter: That’s where all of the information is going to come today.
08:44 Presenter: So we understand, so this is kind of a high level of what people are building.
08:50 Presenter: But actually, one of the questions is basically,
08:54 Presenter: you’re seeing that I’m talking here both about business applications,
08:58 Presenter: professional developers, and about business users.
09:01 Presenter: So everybody in the enterprise is also called citizen developers.
09:05 Presenter: One of the interesting things to understand is how do these technologies find their way into the enterprise?
09:12 Presenter: So how does the typical enterprise end up with low-code, no-code applications being used, being developed by their business users?
09:20 Presenter: And one of the key things to note is that this is really not a choice.
OWASP Top 10 Risks for Low‑Code/No‑Code
09:25 Presenter: The vendors that you see out there on the screen, you can kind of, I’m sure you’ll find one of them at least that most of the organizations
09:36 Presenter: because every SAS vendor today is actually becoming
09:40 Presenter: a low-code, no-code platform.
09:42 Presenter: And there’s a clear reason for that, right?
09:45 Presenter: It’s about extendability, it’s about becoming a platform
09:47 Presenter: rather than a single solution.
09:50 Presenter: So if you think about Salesforce,
09:52 Presenter: it’s far more than a CRM.
09:54 Presenter: It’s a new type of way to build applications,
09:57 Presenter: very similar to the public cloud.
09:59 Presenter: And so when organizations find them,
10:02 Presenter: so as a large organization,
10:05 Presenter: a customer of either Microsoft or Salesforce or ServiceNow
10:08 Presenter: or any other one of the companies that you’re seeing
10:11 Presenter: or Screen or others,
10:12 Presenter: these companies are introducing low-code, no-code capabilities
10:16 Presenter: into their products.
10:17 Presenter: And so low-code, no-code is finding its way
10:20 Presenter: directly into the heart of the enterprise.
10:23 Presenter: And the important thing is that it’s built directly
10:26 Presenter: on top of business data,
10:27 Presenter: because of course, business-sensitive data
10:29 Presenter: sits within each one of these platforms.
10:31 Presenter: And that’s why every enterprise today
10:35 Presenter: according to the statistics that we’ve been able to collect,
10:39 Presenter: with at least five to seven different
10:40 Presenter: low-code, no-code platforms,
10:42 Presenter: and we’re talking about large low-code, low-code platform,
10:45 Presenter: not just the ones that are kind of
10:47 Presenter: a part of a single SaaS solution,
10:49 Presenter: but full-blown platforms that allow developers,
10:53 Presenter: allow business users to build
10:54 Presenter: their own applications and automations.
10:56 Presenter: And so the entire promise around low-code, no-code,
11:01 Presenter: basically comes down to,
11:05 Presenter: we’re trying to basically bring you the key points
11:08 Presenter: behind the promise of low-code, no-code.
11:11 Presenter: First of all, it’s just that the idea
11:14 Presenter: is to accelerate development.
11:16 Presenter: And by accelerating development,
11:18 Presenter: it starts with professional development teams,
11:22 Presenter: putting more power in the hands of developers
11:25 Presenter: and expediting their way to actually get into value.
11:30 Presenter: And it continues with actual business users
11:35 Presenter: to those business users.
11:36 Presenter: And you can see that low code, no code addresses for you
11:40 Presenter: a large number of features that are really,
11:44 Presenter: they’re really complex.
11:45 Presenter: So if you want to, so covering authentication
11:49 Presenter: and authorization, connectors across SAS and on-prem,
11:54 Presenter: development lifecycle, these are things that are important
11:58 Presenter: and are also difficult to get right.
12:02 Presenter: And so low code, no code has a huge promise.
12:05 Presenter: why people are actually using it.
12:08 Presenter: So before we move forward with looking at issues
12:12 Presenter: with low-code, no-code, I think it’s really clear,
12:14 Presenter: it’s really important for all of us to have
12:16 Presenter: a clear example in mind, a clear application
12:21 Presenter: we can think of when we’re thinking about
12:23 Presenter: low-code, no-code applications.
12:25 Presenter: Because one of the things that I’m sure
12:26 Presenter: you’re asking yourself right now is
12:29 Presenter: how critical those applications are.
12:31 Presenter: So when business users are building their applications,
12:35 Presenter: business critical or are they building applications
12:37 Presenter: that are specific to their own needs?
12:40 Presenter: And we’ll see in a moment that business users
12:42 Presenter: are for sure building applications
12:44 Presenter: that can be business critical,
12:46 Presenter: that can be important for the business to operate.
12:50 Presenter: Here’s one example.
12:51 Presenter: So this example actually comes from Microsoft.
12:55 Presenter: So when you visit Microsoft offices physically
13:00 Presenter: and you need to provide your COVID vaccination proof,
13:05 Presenter: is with the low code application,
13:07 Presenter: built with something called portal apps,
13:09 Presenter: part of Power Platform, the local local platform.
13:12 Presenter: And you can see that this application basically allow,
13:16 Presenter: asks you to fill out the form
13:18 Presenter: and upload your vaccine certificate.
13:20 Presenter: Now, of course, this is very sensitive information.
13:24 Presenter: And the way that this information is being stored,
13:26 Presenter: the way that the information is being handled
13:28 Presenter: is very important for Microsoft’s promise.
13:32 Presenter: And so even though it’s built with low-code capabilities, it’s still a very crucial application with critical health data that should be addressed accordingly.
13:45 Presenter: Here’s another example.
13:46 Presenter: This one comes from a use case for Workato.
13:50 Presenter: Workato is an automation platform.
13:52 Presenter: And this example actually comes from Slack
13:55 Presenter: where they automated their entire order to cache processes
14:00 Presenter: with a no code interface.
14:04 Presenter: So this of course is a very important process
14:08 Presenter: and we’re talking about tens of different automations
14:11 Presenter: that are combined together putting information
14:13 Presenter: from multiple different sources.
14:15 Presenter: You can see this can become very, very complex.
14:18 Presenter: And so of course,
14:19 Presenter: And of course, this is very important to get right.
14:22 Presenter: Now, the next example I’m going to show you is going to be a bit different,
14:26 Presenter: and you’ll soon find why.
14:30 Presenter: In this example, this is a story where a team within Microsoft,
14:36 Presenter: actually within the marketing department within Microsoft,
14:39 Presenter: that team was in charge of basically coordinating product releases for lunches
14:45 Presenter: and for conferences.
14:46 Presenter: And they found that they have different processes that are put in place in order to release, to do product releases.
14:53 Presenter: And each product group or each group had different processes and they wanted to streamline it.
15:00 Presenter: So the folks from those teams, again, business users, they created an application that was actually basically a way for them to enforce that process or to streamline that process across all of the teams that they were connecting to.
15:19 Presenter: This took them two days to implement as business users.
15:24 Presenter: And this became the golden standard at Microsoft for this process of optimizing, of kind of going through product launches.
15:36 Presenter: And so this is something that started with a few people that wanted to streamline their own work.
15:41 Presenter: and it ended up as the go-to application to manage product launches
15:47 Presenter: or marketing launches that is used, as you can see on screen,
15:50 Presenter: with 150 different employees across the company.
15:54 Presenter: This is actually taken from Microsoft website.
15:56 Presenter: You can see the link below.
15:58 Presenter: And, of course, and you can see that very shortly,
16:01 Presenter: this became like the go-to standard.
16:04 Presenter: This is something that is built by business users.
16:07 Presenter: And so part of why this example is important is because it represents a shift,
16:16 Presenter: a shift where low-code stops being only tools that professional developers can use
Concrete Examples and Case Studies
16:25 Presenter: and becomes something that business users can use as well to build their own needs.
16:31 Presenter: And that’s a huge gap.
16:33 Presenter: So the next thing I want to show you is to try and figure out when this happened.
16:39 Presenter: When did low-code, no-code become something that is trying to empower business users
16:44 Presenter: rather to make professional development teams more productive?
16:50 Presenter: And so we’ll do that by looking through the lens of Microsoft,
16:55 Presenter: simply because they’re a leader in this space,
16:59 Presenter: and they’ve also shared a lot of their thought leadership throughout the years.
17:03 Presenter: Here’s a quote from Satya Nadella’s speech
17:06 Presenter: at Microsoft Build 2018.
17:09 Presenter: This is where he’s talking about Power Platform
17:12 Presenter: for the first time.
17:13 Presenter: Power Platform is their local, local platform.
17:15 Presenter: And you can see that he’s talking about it
17:17 Presenter: as an extendability framework for dynamics.
17:20 Presenter: This is basically Microsoft’s response to everything.
17:25 Presenter: So this is very similar to what Salesforce has around
17:29 Presenter: customizing your Salesforce instance.
17:33 Presenter: There are partners that help you customize your dynamics
17:38 Presenter: or your Salesforce to fit your organization.
17:40 Presenter: And this is described as a tool for them to be productive.
17:44 Presenter: So Salesforce, for example, has Apex code,
17:46 Presenter: there’s Java integrations.
17:47 Presenter: Today there are also local no-code tools,
17:49 Presenter: we’ll get to that later.
17:51 Presenter: The same thing applies here.
17:52 Presenter: So Microsoft is basically trying to say,
17:54 Presenter: hey, the entire ecosystem around dynamics,
17:58 Presenter: you can now use local no-code capabilities
18:01 Presenter: to accelerate your work.
18:03 Presenter: instead of building things only with .NET extensions.
18:07 Presenter: Let’s see another quote from Satya a year later.
18:11 Presenter: This one, again, a year later,
18:14 Presenter: is a completely different message.
18:16 Presenter: You can see that this shift has,
18:18 Presenter: that there’s a shift in focus
18:19 Presenter: from professional developers to citizen developers,
18:23 Presenter: which is the way that Microsoft calls it.
18:26 Presenter: Now the entire industry is calling business users
18:28 Presenter: that are developing application.
18:30 Presenter: and you can see that there is a clue here to why did they make the shift
18:36 Presenter: and that clue is that two and a half million citizen developers
18:39 Presenter: already using Power Platform.
18:41 Presenter: So, of course, the number of business users is far larger
18:44 Presenter: than the number of professional developers.
18:47 Presenter: And so, of course, it makes total sense for vendors
18:51 Presenter: to try and open up the market of users that can use those platforms
18:57 Presenter: because it can also provide a lot of value for companies.
19:00 Presenter: You can also see in the second quote,
19:02 Presenter: why this is so important.
19:04 Presenter: This explains the shift.
19:06 Presenter: Microsoft is looking at this as the new Excel,
19:08 Presenter: the new way to provide business users,
19:12 Presenter: to empower business users,
19:14 Presenter: to actually solve their own needs.
19:16 Presenter: And this is far larger than Microsoft now.
19:18 Presenter: We’re seeing this across the industry.
19:21 Presenter: This is a very large shift to make in one year.
19:25 Presenter: And it also shows us
19:27 Presenter: kind of the way that low-code got from one place to another,
19:31 Presenter: from targeting only professional developers
19:33 Presenter: to targeting business users as well.
19:36 Presenter: Three years later, this is a quote from last year,
19:40 Presenter: from Satya, you can see that Microsoft already has
19:43 Presenter: 20 million active users using their low-code,
19:46 Presenter: low-code platform.
19:46 Presenter: So a 10x growth, about a 10x growth in three years.
19:50 Presenter: And again, this just shows you how successful
19:54 Presenter: this technology here is,
19:57 Presenter: to different organizations.
20:00 Presenter: This was all looking through the Microsoft Lens,
20:03 Presenter: but this is actually a story about the entire industry.
20:05 Presenter: So we can see Salesforce doing the same,
20:08 Presenter: ServiceNow are talking about in the same message,
20:10 Presenter: WorkCarto is doing the same.
20:12 Presenter: Other vendors are looking to expand
20:14 Presenter: beyond professional development to business users as well.
20:19 Presenter: And so before we move forward,
20:21 Presenter: it’s really important that we understand
20:23 Presenter: just how easy it is to create those applications,
20:27 Presenter: this is crucial for us, for you to trust me
20:30 Presenter: that this is actually something
20:31 Presenter: that business users can actually build.
20:33 Presenter: And so let me show you an example.
20:36 Presenter: And this is going to be kind of a very quick example,
20:40 Presenter: what I’ll show here,
20:43 Presenter: and you’ll see the video in a moment.
20:47 Presenter: Okay, so what I’m going to show you
20:51 Presenter: is a very kind of simple example.
20:54 Presenter: Basically, my organization is using Slack,
Summary, Takeaways, and Q&A — Part 1
20:57 Presenter: And one of the things that happens in Slack is that people mention you on a public channel,
21:03 Presenter: and they expect a response pretty quickly.
21:06 Presenter: And so kind of as a joke, I wanted to create an application that allowed me to basically appear as if I’m on a call.
21:14 Presenter: So this automation that I’m creating right now is every time that somebody mentions me on a Slack channel,
21:22 Presenter: the automation is going to trigger.
21:25 Presenter: It’s going to change my status as if I’m on a call with a call status,
21:30 Presenter: with a call logo.
21:31 Presenter: And then it’s going to wait for like five minutes,
21:34 Presenter: and then it will change my status again as if I’m active.
21:38 Presenter: Now, of course, this is a joke,
21:39 Presenter: but you can see how quickly I can build this thing.
21:43 Presenter: So while I’m talking to you, this thing gets built.
21:45 Presenter: And just think about the number of things that Zapier had to handle
21:51 Presenter: for this thing to work.
21:52 Presenter: And by the way, right now you’re seeing the publish button.
21:55 Presenter: This publish button is basically a combined button
21:58 Presenter: that does two things.
22:00 Presenter: One is save and the other is deployed to production,
22:02 Presenter: which is kind of interesting.
22:04 Presenter: And so again, let’s think about all of the things
22:07 Presenter: that Zapier had to handle in order for these things
22:10 Presenter: to work.
22:11 Presenter: So there’s authentication to Slack that needs to work here.
22:16 Presenter: There’s a secret, right?
22:17 Presenter: Because my identity is there somewhere
22:19 Presenter: in order to connect to Slack.
22:20 Presenter: You need to subscribe to Webhook.
22:22 Presenter: You need to support APIs and the different changes
22:25 Presenter: You need to be able to delay for five minutes
22:28 Presenter: or something need to operate behind the scenes.
22:31 Presenter: There’s a, this is a significant piece of software.
22:35 Presenter: It’s not just like a small script that somebody created
22:39 Presenter: and it’s all being built with no code.
22:41 Presenter: It’s all being built with drag and drop
22:43 Presenter: without really understanding what’s going on behind it.
22:47 Presenter: And again, the most important thing here to think about
22:50 Presenter: when we’re thinking in a security perspective
22:52 Presenter: is the identity.
22:53 Presenter: How does this application run?
22:55 Presenter: How does it connect to Slack?
22:57 Presenter: If I’m going to look from the logs, from Slack’s logs,
23:01 Presenter: what’s actually going on here?
23:02 Presenter: What’s happening?
23:03 Presenter: And so we’ll bring down to it in a minute,
23:06 Presenter: but just not to keep you hanging,
23:08 Presenter: this is running with my own identity.
23:10 Presenter: So this is running as if I have done it myself.
23:14 Presenter: And that’s kind of the crucial piece here.
23:17 Presenter: And so now that we understand
23:21 Presenter: how easy it is to create low-code, no-code applications.
23:24 Presenter: Let me try and switch back to the deck.
23:32 Presenter: Okay, so now that we understand just how easy it is
23:35 Presenter: to connect to, to create those applications,
23:40 Presenter: the next thing I want to kind of discuss is,
23:43 Presenter: I mean, we understand how easy it is
23:45 Presenter: to create those applications.
23:46 Presenter: We’ve also seen the huge growth in numbers.
23:51 Presenter: What I’m trying to capture here is the fact that there is a culmination of three different things that are happening at the same time.
24:01 Presenter: One is that major vendors across the industry have a strong incentive to grow the number of users that are using their platforms
24:10 Presenter: and to expand the value that they can provide across the industry.
24:16 Presenter: that by targeting business users, by empowering business users. These are vendors that are
24:21 Presenter: already inside organizations, so there’s no choice. There’s no choice on whether or not
24:26 Presenter: this will happen in your organization. It’s going to happen. The question is, how soon will you get
24:31 Presenter: on top of it? The second point is that companies are actually looking for this. So companies are
24:38 Presenter: lacking IT resources, companies are looking to do digital transformation. This is a way to
24:46 Presenter: to actually solve their own problems.
24:48 Presenter: And so this is a really cool piece of technology
24:50 Presenter: that could provide a lot of business value.
24:52 Presenter: And the third piece here is that unlike previous attempts
24:56 Presenter: to try and actually put more power
24:59 Presenter: in the hands of business users,
25:00 Presenter: this is actually working.
25:02 Presenter: So this is achievable for business users
25:05 Presenter: that are not development professionals
25:09 Presenter: to build their own applications.
25:11 Presenter: And that’s why it’s important
25:13 Presenter: to address low-code, no-code right now.
25:18 Presenter: So now that we understand what no code, no code is,
25:21 Presenter: and how did we get here,
25:23 Presenter: the last thing I want to tackle
25:25 Presenter: before I go into concrete risks
25:28 Presenter: is how these applications get developed.
25:30 Presenter: So how does the SDLC look like for low code, no code?
25:34 Presenter: This is a kind of a traditional low code,
25:37 Presenter: this is a traditional SDLC,
25:38 Presenter: nothing low code, no code specific about it.
25:41 Presenter: So I’ll kind of skip directly through it.
25:44 Presenter: This is my attempt to try and say, okay, who’s in charge of each one of those things?
25:48 Presenter: Now, of course, this will change between different organizations, between different types of applications.
25:54 Presenter: But kind of in a high level, the business is in charge of basically putting the need out there.
26:00 Presenter: Engineering is in charge of creating it, planning it and creating it.
26:04 Presenter: There might or might not be QA as a separate discipline.
26:09 Presenter: And there’s also kind of deployment, monitoring, production.
26:14 Presenter: those things that are about making sure
26:15 Presenter: that the applications are actually operating as expected.
26:19 Presenter: The only reason that I pointed this out there,
26:21 Presenter: because of course these things are,
26:23 Presenter: this is kind of trivial,
26:25 Presenter: is to try and distinguish how low-code, no-code looks
26:28 Presenter: next to this SDLC.
26:34 Presenter: And this is kind of the key point
26:37 Presenter: about how low-code, no-code gets created.
26:40 Presenter: Now, what I’m basically saying here is that the business
26:44 Presenter: or the person who’s creating the application
26:46 Presenter: can do everything in the SDLC.
26:49 Presenter: This of course is one side of the spectrum.
26:54 Presenter: On the other side of the spectrum,
26:56 Presenter: there are professional development teams using SDLC
26:59 Presenter: as you would expect with professional development.
27:03 Presenter: And so this happens as well,
27:04 Presenter: but the entire spectrum is out there.
27:06 Presenter: We’re also seeing developers that are using low code, no code
27:11 Presenter: with this kind of hit save to deploy changes approach
27:15 Presenter: where there’s not kind of any official planning
27:18 Presenter: or any official QA or verification.
27:22 Presenter: So it’s not that, so some teams are doing it,
27:26 Presenter: but there’s nothing, but it’s very difficult
27:29 Presenter: to enforce them to do it.
27:31 Presenter: And one of the things that we’re seeing again and again
27:33 Presenter: is that the tools around applying SDLC,
27:37 Presenter: true SDLC to low-code, non-code, they’re really lacking.
27:41 Presenter: are trying their best to apply the lessons learned
27:43 Presenter: from professional development to development
27:46 Presenter: with low code, no code, they’re finding it challenging
27:48 Presenter: because there’s no code to scan,
27:50 Presenter: there’s no easy way to plug into CICD in many cases,
27:55 Presenter: there’s no one time monitoring.
Summary, Takeaways, and Q&A — Part 2
27:57 Presenter: So, and again, this depends,
27:59 Presenter: it’s very difficult to discuss these topics
28:02 Presenter: across different platforms
28:03 Presenter: because every platform would be different
28:05 Presenter: and some platforms are having a more mature SDLC than others,
28:11 Presenter: In general, SDLC for low-code, no-code is far more immature than the professional development SDLC.
28:20 Presenter: And this is also at the root of two things.
28:26 Presenter: One is at the root of many security issues that we’ll find that we’ll see in a moment.
28:31 Presenter: And the other side is that this is also at the root of why low-code, no-code is so successful,
28:35 Presenter: because it allows you to do things quickly.
28:38 Presenter: There is one stakeholder that can do everything from thinking about the need to solving the need for their own.
28:45 Presenter: And so one thing that you might be thinking right now when I’m talking about these kind of issues is who’s in charge?
28:53 Presenter: Who needs to own the risk that is being created by local local applications?
28:59 Presenter: And you might be tempted to think that the people that are in charge here should be the platforms themselves.
29:04 Presenter: So the people that have put this platform,
29:06 Presenter: that are creating the local, local platforms,
29:09 Presenter: and they should be in charge of the applications
29:11 Presenter: that are being created by those platforms.
29:14 Presenter: Or in other words, you could be thinking,
29:16 Presenter: hey, why don’t the platform vendors make sure
29:20 Presenter: that every application created by their platform is secure?
29:24 Presenter: Now, this, we’ve actually learned,
29:27 Presenter: we’ve actually tried this before, and this failed,
29:30 Presenter: and we’ve come across a better solution.
29:33 Presenter: This is the same shared responsibility model that we’ve seen in the public cloud.
29:39 Presenter: So when the public cloud started, it took us as an industry some time to figure out that basically,
29:46 Presenter: while the public cloud is, while AWS, GCP, Azure, they are in charge of making sure the platform itself is secure
29:57 Presenter: and that the building blocks are secure.
29:59 Presenter: Of course, as an organization that builds something in the cloud,
30:02 Presenter: we’re in charge of what we’re building.
30:04 Presenter: There’s no other way.
30:05 Presenter: If you’re building something, you are in charge of the business logic.
30:09 Presenter: You understand what is feasible for your organization or not.
30:12 Presenter: The vendors, they’re in charge of putting the building blocks for you,
30:15 Presenter: but you’re all in charge of what you’re creating.
30:17 Presenter: And this is the same thing for low code, no code.
30:19 Presenter: And so the OWASP top 10 risks for low code, no code,
30:24 Presenter: focus on the customer’s side of the shared responsibility model.
30:29 Presenter: rather than the platform.
30:30 Presenter: Of course, we need to push the platforms
30:35 Presenter: to own their part as well.
30:37 Presenter: And actually most platforms are doing it pretty well
30:40 Presenter: from my perspective.
30:42 Presenter: But the part where we need to own the applications
30:46 Presenter: that we’re building, this is what’s missing.
30:48 Presenter: And this is what the OWASP Top 10 is focused on.
30:54 Presenter: And so without further ado,
30:57 Presenter: we’re going to talk about the OWASP top 10 risk for low-code, no-code.
31:01 Presenter: And before I show you the concrete list, I’m going to say that,
31:06 Presenter: I’m going to share that there are basically two goals for my talk today.
31:10 Presenter: One goal is just to spread this information out there and
31:14 Presenter: to help the entire industry grow our understanding of this space.
31:19 Presenter: And the second piece is that we want more people involved in the low-code, no-code group.
31:22 Presenter: So there are already people joining us
31:25 Presenter: from across the industry, from Microsoft and Palo Alto
31:28 Presenter: and other large and small companies as well.
31:32 Presenter: Vendors, people that are using low code, no code
31:35 Presenter: to build their own applications.
31:37 Presenter: The larger perspective we’ll have on this problem,
31:40 Presenter: the better.
31:41 Presenter: And so the list that you’re going to see today
31:44 Presenter: is a result of the scan of more than 100,000
31:50 Presenter: different low code, no code applications
31:52 Presenter: earlier across the industry, across different local,
31:56 Presenter: local platforms, and that was the basis
31:59 Presenter: of finding out those problems,
32:02 Presenter: of finding out what are the problems
32:03 Presenter: that we see with local, local, and then the group,
32:07 Presenter: and then the group debated on categories
32:09 Presenter: and then thinking about how do we separate this
32:12 Presenter: into categories that make sense.
32:14 Presenter: And we’d be, if you’re interested in kind of,
32:17 Presenter: in joining the group, in getting information,
32:20 Presenter: getting kind of access to information behind it
32:23 Presenter: in contributing yourself,
32:24 Presenter: please reach out to me after this talk.
32:29 Presenter: And so these are the top 10 for low code, no code,
32:32 Presenter: and we’re going to go through each one.
32:34 Presenter: So that’s kind of the next step.
32:42 Presenter: Okay.
32:45 Presenter: We’ll start with the first thing,
32:47 Presenter: which is account impersonation.
32:50 Presenter: that we saw when I created this API example
32:52 Presenter: is that identity was really not part
32:55 Presenter: of what I had to do there.
32:57 Presenter: It was kind of implicit.
32:58 Presenter: Now, when you think,
33:00 Presenter: think kind of as a low code, no code platform,
33:03 Presenter: when you want to expand within an organization,
33:07 Presenter: you want people to adopt your platform
33:08 Presenter: and to build a lot of application with it.
33:11 Presenter: The number one thing that will block you
33:14 Presenter: in an enterprise is actually permissions.
33:17 Presenter: If every user, business user, would have to ask for permissions from IT to build their own application,
33:25 Presenter: before they actually build it, you won’t see the exponential growth that you saw in the graph earlier.
33:31 Presenter: So the way that this gets circumvented is that business users can embed their own identities within application,
33:38 Presenter: of course, not just business users, professional developers as well,
33:40 Presenter: and this allows the applications to be built very rapidly.
33:46 Presenter: When you get to a place where you want to build an application,
33:51 Presenter: you give that application the ability to operate on your behalf.
33:54 Presenter: And then every user of that application ends up using your identity.
33:58 Presenter: Let’s see an example.
34:00 Presenter: So, and this is a real example.
34:02 Presenter: So this is a customer care team from a large e-commerce company.
34:06 Presenter: They basically had a problem where people that were involved in support cases for customers
34:12 Presenter: didn’t have the entire context about that customer.
34:14 Presenter: And they didn’t have a way to, so they wanted to share the information that they had about the customer with people relevant to the case.
34:22 Presenter: They created an application that allowed, that basically used the customer care team identity to fetch information from the database behind it.
34:34 Presenter: And every employee that had a relation to some case, to some support case, was able to see information about relevant customers.
34:44 Presenter: employees only having the ability to view information
34:47 Presenter: about customer cases that they are related to.
34:50 Presenter: So it seems like everything’s fine, right?
Summary, Takeaways, and Q&A — Part 3
34:53 Presenter: Permissions are being granted kind of in the right way.
35:00 Presenter: So it seems like the problem is solved.
35:03 Presenter: Employees are happy because they are able
35:05 Presenter: to address customer needs better.
35:07 Presenter: Customers are happy because their tickets
35:09 Presenter: get answered better.
35:10 Presenter: And the customer care team is happy because, well,
35:15 Presenter: in an easier way across the organization.
35:18 Presenter: What’s the problem here?
35:21 Presenter: Well, of course, imagine this from the SOX perspective.
35:24 Presenter: Imagine this from the security perspective.
35:26 Presenter: This is an application.
35:28 Presenter: A lot of people in the organization
35:30 Presenter: are using this application,
35:32 Presenter: but they are all using the same underlying identity,
35:35 Presenter: which in this case was admin credentials
35:37 Presenter: to the customer database.
35:38 Presenter: So from the SOX perspective, they get an alert,
35:41 Presenter: which looks like abnormal activity, right?
35:44 Presenter: it looks like somebody has stolen this admin credential
35:47 Presenter: and is now querying the database across the organization
35:51 Presenter: with different queries that perform
35:54 Presenter: from different IPs and hosts across time.
35:57 Presenter: And so from the SOC perspective, of course,
35:59 Presenter: this looks like a hack.
36:01 Presenter: And so what happened here was that the SOC
36:03 Presenter: started to ask around to understand.
36:06 Presenter: And the first thing that they did is to investigate
36:09 Presenter: the user that was being used.
36:11 Presenter: And that user was actually the same user
36:14 Presenter: And so once they are able to reach out to the team there,
36:18 Presenter: they figured it out, they understood what actually happened
36:21 Presenter: that the application is embedding
36:22 Presenter: the makers own identity within the app.
36:25 Presenter: And so what ended up happening as a,
36:29 Presenter: so of course the mitigation here is pretty obvious, right?
36:31 Presenter: The mitigation is that every user needs to be able
36:34 Presenter: to access the application with their own identity.
36:37 Presenter: And the underlying connections to the data
36:39 Presenter: should also be only for their own identity.
36:42 Presenter: And this is a pattern that we see again and again.
36:45 Presenter: This is not a problem only with Zapier as we saw earlier,
36:47 Presenter: it’s across different local, local platform.
36:50 Presenter: It’s actually a fundamental way in which we see
36:52 Presenter: local, local platforms accelerate and build their audience.
36:57 Presenter: And so this was kind of, and this was one example.
37:03 Presenter: Moving forward, the next category is authorization.
37:08 Presenter: Now, authorization of course is a big deal.
37:12 Presenter: Because low-code, no-code platforms are only as useful as the applications that they can access.
37:20 Presenter: Services that they can access, SaaS services, on-prem, everywhere.
37:24 Presenter: And low-code, no-code platforms have figured out ways to actually get connected to the entire organization very quickly.
37:33 Presenter: So if you open up a popular low-code, no-code platform today, you’ll typically see hundreds of integrations that are just waiting for you,
37:39 Presenter: including things that can happen,
37:41 Presenter: that can, including on-prem gateways
37:43 Presenter: or ways to fetch information
37:45 Presenter: or push information to on-prem.
37:47 Presenter: And so this leads to something that we see again,
37:53 Presenter: in multiple platforms, which is credential sharing.
37:57 Presenter: And so when you saw me create that application earlier,
38:00 Presenter: earlier with JPR, and I explained that this application
38:04 Presenter: is actually using my identity,
38:07 Presenter: one thing that happens there on top of that
38:11 Presenter: is that when I finish creating my identity,
38:15 Presenter: which actually means basically an OAuth popup window,
38:18 Presenter: I plug in my credentials and I store my refresh token.
38:21 Presenter: Now there’s a nice little share button.
38:24 Presenter: And you can see here on screen, default environments
38:28 Presenter: or notions of default environments
38:29 Presenter: across different platforms where credentials
38:32 Presenter: are being shared as a feature of the platform.
38:36 Presenter: Again, the platforms are allowing users to embed,
38:40 Presenter: to log in to a SaaS service or to a SQL server
38:44 Presenter: or to Office or to Gmail.
38:46 Presenter: And then these connections, these credentials
38:52 Presenter: can be shared with other users.
38:54 Presenter: And they can be shared explicitly.
38:57 Presenter: So just click on share and share it with somebody else.
39:02 Presenter: by embedding them within applications.
39:05 Presenter: And so low-code, non-code platforms have actually built something that is,
39:11 Presenter: as I write here in the title, credential sharing as a service.
39:16 Presenter: Now, again, there’s a reason behind it.
39:18 Presenter: This is a great accelerator for productivity.
39:25 Presenter: But, of course, the security implications are dire
39:28 Presenter: because once an attacker gets into one of those platforms,
39:32 Presenter: they already have a bag of credentials that they can leverage.
39:35 Presenter: Let me show you another example of authorization
39:39 Presenter: of using or issues with authorization.
39:43 Presenter: So one other typical anti-pattern that we see
39:46 Presenter: is that in many cases, it’s very difficult to figure out
39:50 Presenter: what are the APIs that are working
39:52 Presenter: behind a low-code application.
39:54 Presenter: And so in order to make it easier in the development phase,
39:59 Presenter: we see users doing the following thing.
40:03 Presenter: They provide all of the users of their application
40:07 Presenter: with full admin APIs to the kind of an admin role
40:12 Presenter: to the API and then distinguish between different roles
40:17 Presenter: of users to their application with the client side with the one.
40:20 Presenter: So on the client side, you won’t see the ability to,
40:24 Presenter: for example, go into the admin panel.
40:26 Presenter: But of course, if you just use the APIs,
40:29 Presenter: you can go ahead and use it.
40:30 Presenter: Now, of course, this requires you to understand
40:33 Presenter: the distinction between front-end and back-end,
40:37 Presenter: between APIs and client-side,
40:39 Presenter: and this is an ask that is,
40:42 Presenter: that’s a big ask when you ask it from business users.
40:46 Presenter: And also, as developers, we can also make mistakes, right?
40:49 Presenter: So, and it’s very difficult to make,
40:51 Presenter: to prevent mistakes only with manual intervention.
40:55 Presenter: And so we’ve seen a couple of examples of authorization misuse, but again,
41:02 Presenter: this is something that we see again and again across these different platforms,
41:06 Presenter: especially because low-code, no-code platforms are only as strong as the connections
41:13 Presenter: that they make outside of the platform.
41:17 Presenter: This also brings us to the next part, which is data leakage.
41:20 Presenter: And so of course, as platforms that move data around,
41:24 Presenter: there’s a large risk of data leaking out of organizations.
41:27 Presenter: And so let me show you one example of that
41:29 Presenter: with a concrete application.
41:31 Presenter: This is something that we see,
41:32 Presenter: this is a concrete example,
41:34 Presenter: and you’re seeing this again and again.
41:36 Presenter: Essentially, users are trying to move,
41:43 Presenter: trying to sync their email address
41:46 Presenter: from their corporate account to their personal account.
41:50 Presenter: that users have been trying to do for years, right?
Summary, Takeaways, and Q&A — Part 4
41:52 Presenter: And there are plenty of solutions to try and stop that.
41:56 Presenter: So DLP and things you can put in your email.
42:00 Presenter: And so the way that users are doing it today
42:03 Presenter: with low-code, low-code is that instead of forwarding emails,
42:07 Presenter: they’re simply copying contents.
42:09 Presenter: And so nobody will ever know, right?
42:11 Presenter: Because the copy is being used,
42:14 Presenter: is being done by the low-code, low-code platform
42:16 Presenter: in the low-code, low-code cloud.
42:18 Presenter: it’s being used with two different identities,
42:21 Presenter: one for the corporate account, one for the personal account,
42:23 Presenter: and the email server doesn’t even know that it happened.
42:26 Presenter: So the email server only sees you,
42:29 Presenter: you log into your email, you get an email, that’s it.
42:32 Presenter: They don’t know that you’re, that another,
42:35 Presenter: that somewhere else, the local local platform
42:37 Presenter: is pushing that email to another location.
42:41 Presenter: And so this is something that we’re seeing again and again,
42:43 Presenter: it’s not only happening with emails,
42:45 Presenter: It’s happening with drives and with any sort of file share.
42:50 Presenter: And we’re seeing this with different platforms
42:53 Presenter: and different vendors as well.
42:55 Presenter: Actually, across all of the different organizations
42:58 Presenter: that were part of the statistics that you’re seeing here,
43:00 Presenter: we saw this example at least once.
43:04 Presenter: Here’s another example.
43:06 Presenter: This one is simply showing you the power
43:09 Presenter: that low-code, no-code has to cause harm.
43:12 Presenter: And so in this example,
43:16 Presenter: quick automation, it is triggered manually, it lists out a SharePoint folder, and then it goes
43:22 Presenter: through each SharePoint file and simply encrypts it. And it uses it and it does it with an encryption
43:30 Presenter: step that is helpfully provided by the platforms themselves, because of course there are valid
43:36 Presenter: use cases to encrypt things. And so you can see that malicious intenders can actually use this
43:45 Presenter: And we’ve actually seen this in a few examples,
43:49 Presenter: that this is not the subject of this talk,
43:52 Presenter: but if you’re interested, reach out to me afterwards,
43:55 Presenter: I’ll be happy to share links.
43:59 Presenter: Here’s the next one.
44:00 Presenter: So, when you connect to multiple different locations,
44:04 Presenter: of course, you need to make decisions about the way
44:05 Presenter: that these connections are being made.
44:07 Presenter: And again, keep in mind that the person making that decision
44:11 Presenter: is the developer.
44:12 Presenter: It could be a professional developer.
44:15 Presenter: Now, if you ask a business user the difference
44:18 Presenter: between FTP and FTPS, it really doesn’t make sense.
44:21 Presenter: It doesn’t make sense for them to be the ones
44:23 Presenter: that are asked to answer these questions.
44:26 Presenter: So of course, mistakes are happening.
44:30 Presenter: Let me move forward.
44:31 Presenter: The next thing that we’re seeing
44:34 Presenter: is security misconfiguration.
44:36 Presenter: Now, this is more than just misconfiguration alone.
44:42 Presenter: This is very similar to the types of misconfiguration
44:45 Presenter: and issues we’re seeing in cloud,
44:47 Presenter: because other than the fact that things
44:48 Presenter: are getting misconfigured,
44:50 Presenter: they are getting misconfigured in a way
44:52 Presenter: that can be expected,
44:54 Presenter: in a way that can be enumerated.
44:56 Presenter: And that’s the problem.
44:57 Presenter: Let me give you an example.
44:59 Presenter: This is actually an issue found by a team at UpGuard
45:04 Presenter: at 2021.
45:07 Presenter: Basically, one of the types of applications
45:10 Presenter: that Microsoft local platform can create,
45:13 Presenter: is an application that is exposed to the outside world,
45:15 Presenter: and it creates an API automatically.
45:19 Presenter: That application is supposed to be used as a portal,
45:24 Presenter: as an outbound facing portal.
45:26 Presenter: And so this means that you need to be able to,
45:31 Presenter: so anonymous users should be able to use it as well
45:34 Presenter: before they log in.
45:35 Presenter: The problem here is by default,
45:37 Presenter: all of the information behind the website
45:39 Presenter: was exposed through API to anonymous users.
45:43 Presenter: at Apgarve identified that, they were able to scan
45:46 Presenter: through the internet, of course, all of these websites
45:48 Presenter: are in a single domain, a subdomain of a single domain.
45:52 Presenter: They were able to find those websites
45:53 Presenter: and actually get to business information
45:58 Presenter: that was being kind of kept by those applications.
46:04 Presenter: Now, since then, Microsoft has rapidly changed the default,
46:08 Presenter: but of course, the fact that the default is now secure
46:11 Presenter: doesn’t mean that people cannot misconfigure things.
46:13 Presenter: And so here’s an example, and this is a real example.
46:17 Presenter: Portals are being shared, are being created in this domain.
46:22 Presenter: So it’s a subdomain portal, replace portal with your name.
46:26 Presenter: In the domain, powerappsportals.com.
46:30 Presenter: And if you go to this URL here,
46:32 Presenter: you’ll get to the anonymous endpoint
46:33 Presenter: which exposes the information
46:35 Presenter: if the thing is misconfigured.
46:37 Presenter: Here’s an example.
46:38 Presenter: So this is a real example from an application that we found
46:44 Presenter: kind of looking through different applications
46:46 Presenter: that were out there on the internet.
46:48 Presenter: We were able to find an application that exposed this endpoint.
46:52 Presenter: When you look at this endpoint, you’re seeing the three different entities
46:55 Presenter: that are available for query.
46:56 Presenter: One is a default entity, which really doesn’t have anything.
46:59 Presenter: The second one is entity form set, which is just where form submissions are being stored.
47:05 Presenter: The third one is global variables,
47:07 Presenter: which is kind of interesting, right?
47:09 Presenter: So let’s see what global variables contains.
47:13 Presenter: Of course, it contains authentication,
47:16 Presenter: an OAuth token with access to Azure,
47:19 Presenter: because this is global variables used by the applications.
47:23 Presenter: And so this is a real example.
47:24 Presenter: Of course, we’ve submitted this vulnerability disclosure
47:28 Presenter: to the relevant company, which quickly solves it.
47:31 Presenter: But you can see that this type of problem
47:35 Presenter: to the S3 bucket problem,
47:38 Presenter: open S3 bucket problem we’ve had
47:41 Presenter: with cloud for a long time now.
47:45 Presenter: Moving on, because I see that we don’t have a lot of time,
47:49 Presenter: so forgive me if I kind of skim
47:53 Presenter: through a few of those categories here.
47:56 Presenter: The next part is about injection selfies.
48:00 Presenter: And so of course, these applications expose endpoints,
48:02 Presenter: these end points are prone to injection.
48:06 Presenter: The vendors themselves can try and figure out
48:10 Presenter: and basically sanitize user input.
48:13 Presenter: But of course it really matters what you do
48:14 Presenter: with that user input.
48:15 Presenter: You can’t sanitize input for any type of injection.
48:19 Presenter: It depends whether it goes to a SQL server,
48:22 Presenter: it goes to a JSON parser, it executes its codes.
48:24 Presenter: There are a whole bunch of things that you can see
48:26 Presenter: with information being used by local, no code apps.
48:30 Presenter: And this is actually very similar to the injection surface
48:33 Presenter: that is being exposed by serverless applications,
48:36 Presenter: where you have these triggers that are not only web hooks,
48:42 Presenter: but they can be a file,
48:43 Presenter: they can be an object that is being shared.
Summary, Takeaways, and Q&A — Part 5
48:49 Presenter: One other thing that is crucial with low code, no code,
48:53 Presenter: and we’ve actually seen this in questions as well,
48:55 Presenter: is that this is just another way
48:57 Presenter: where supply chain issues can occur.
49:00 Presenter: Of course, low code, no code only works
49:03 Presenter: because there’s a large number of widgets and components
49:07 Presenter: that are ready for you to pick up and use.
49:09 Presenter: And once you do that, of course, this is an ability
49:13 Presenter: for third party connectors or third party software
49:18 Presenter: to be introduced into your application.
49:20 Presenter: Now, just imagine how would you find
49:23 Presenter: which low-code, no-code applications in your organization
49:27 Presenter: are actually running Log4J.
49:30 Presenter: This is, of course, a real example.
49:33 Presenter: And this is a huge problem.
49:36 Presenter: So we’ve actually been collaborating with the Cyclone DX team
49:39 Presenter: to get low-code integrated into the next release of their SBOM standard
49:48 Presenter: to try and address this issue.
49:53 Presenter: Okay, next up, there’s data and secrets.
49:58 Presenter: Of course, applications,
50:02 Presenter: business critical applications touch business critical data.
50:05 Presenter: They also need to store secrets.
50:07 Presenter: Those secrets can be used for authentication
50:09 Presenter: or to systems across the company.
50:15 Presenter: And so let me give you a concrete example.
50:18 Presenter: And this is from a large IT company.
50:21 Presenter: their HR team created an application that was used to facilitate a giveaway campaign.
50:27 Presenter: So you donate money to charity, you decide which charity you want to donate money to,
50:31 Presenter: and you need to provide your credit card so they’ll be able to charge you.
50:35 Presenter: Now, the thing is, the problem is that the HR team really doesn’t know how to store credit cards, nor should they.
50:42 Presenter: So the credit cards ended up being stored on a default database in plain text
50:48 Presenter: available to the entire organization including guests.
50:52 Presenter: Now this is a kind of a silly example, but it’s a real world example.
50:56 Presenter: And again, it’s not something, we should not be demanding HR teams to figure out how to store credit cards.
51:03 Presenter: We should create guardrails that allow them to work properly and to solve their own needs
51:09 Presenter: and to automatically point them in the right direction.
51:16 Presenter: I’m going to cover the last two categories briefly,
51:21 Presenter: and then I’m going to go to summary and questions.
51:24 Presenter: And so the next category is about asset management.
51:29 Presenter: When you think about so many applications being developed,
51:32 Presenter: so you saw about 75,000 different applications
51:35 Presenter: in the statistics I saw earlier in a single organization.
51:41 Presenter: You can imagine how many of these applications are stale
51:43 Presenter: or applications that no longer have an owner
51:47 Presenter: because the person who’s created them has already moved roles
51:50 Presenter: like three times in the organization and has left the organization.
51:53 Presenter: Finding out where those applications are,
51:57 Presenter: bringing the applications that are business critical under the IT umbrella
52:00 Presenter: is a huge challenge.
52:01 Presenter: And it is required not only to reduce kind of complexity and to reduce technical debt,
52:08 Presenter: but actually to make sure that applications that are business critical, somebody’s looking after them.
52:13 Presenter: And when the creative employee that has created this application leaves the organization,
52:17 Presenter: the organization just doesn’t get stuck.
52:20 Presenter: And the last thing, the last category, is about monitoring and logging.
52:25 Presenter: When you think about the ability of a security team to respond to a threat, to respond to a hack that has something to do with a low-code, no-code application, the ability of that security team to figure out what happened is really small.
52:43 Presenter: It’s really difficult because the logs that these platforms generate are mostly not sufficient or not up to the standards that we’ve seen from other applications.
52:56 Presenter: generalizing here, some platforms are better than others.
53:00 Presenter: But it’s important to note that the level of maturity
53:04 Presenter: of low code with logging, with monitoring,
53:08 Presenter: and also with runtime security,
53:11 Presenter: it’s simply not there.
53:14 Presenter: It’s not as sufficient as it should be.
53:16 Presenter: And so of course, this limits the ability
53:19 Presenter: of security teams to respond to issues.
53:24 Presenter: Now, thank you for bearing with me, and I’m sorry for kind of a bit of,
53:29 Presenter: rationing it a bit at the end.
53:30 Presenter: I wanted to make sure we leave enough time for summary and maybe going through a couple of questions.
53:37 Presenter: And so now that we’ve seen the top 10 and we’ve seen that these issues, so one thing that you can
53:44 Presenter: spot kind of thinking about and retrospectively is the fact that these issues cover both professional
53:50 Presenter: development and business development. Now, yes, the fact that business users are creating
53:56 Presenter: applications can introduce more risk by the fact that they are not security savvy. But of course,
54:02 Presenter: professional developers using low code, they need help too, right? When professional developers
54:09 Presenter: build applications with code, there are so many tools that help them make sure that they
54:14 Presenter: catch mistakes early.
54:16 Presenter: There’s application security and runtime monitoring
54:18 Presenter: and gating and behavioral analytics.
54:23 Presenter: There’s a whole bunch of things that we’re putting out
54:25 Presenter: and processes like security review.
54:28 Presenter: So many processes, so many tools
54:30 Presenter: that are there to help developers spot mistakes early.
54:34 Presenter: With low code, no code, this is really difficult.
54:37 Presenter: And usually you’ll find that the processes
54:41 Presenter: are either lacking or they’re simply not there at all.
54:46 Presenter: And so here’s what we’ve seen today.
54:48 Presenter: We’ve seen that low code, no code is rapidly growing
54:51 Presenter: across the enterprise.
54:53 Presenter: And it’s probably already in your organization
54:55 Presenter: because it comes from many different places,
54:57 Presenter: but including vendors that you’ve already been using
55:01 Presenter: and they have been expanding into a low code, no code platform.
55:05 Presenter: We’ve seen that low code, no code is shifting
55:07 Presenter: from focusing only on professional developers
55:11 Presenter: and business users as well.
55:12 Presenter: And today, low-code, no-code platforms cover both.
55:15 Presenter: They target both professional developers
55:18 Presenter: and business users and anything in between.
55:21 Presenter: We’ve seen that low-code, no-code significantly
55:24 Presenter: is missing SDLC or is missing maturity in SDLC.
55:28 Presenter: And we’ve seen the top 10 risks
55:30 Presenter: that you should address for low-code, no-code.
55:32 Presenter: So if you’re worried about this space,
55:34 Presenter: you’re thinking about this space,
55:36 Presenter: this is where you should focus.
55:37 Presenter: Now, I encourage you,
55:41 Presenter: in this space, reach out to me, you can easily find my credentials,
Summary, Takeaways, and Q&A — Part 6
55:46 Presenter: reach out to the OS group, we are always looking for collaborators.
55:54 Presenter: Here’s one slide about what you can take from this talk. So there’s a huge opportunity here
56:01 Presenter: because we’re finding this, you’re seeing how fast this chart goes or how many applications
56:07 Presenter: are being developed.
56:08 Presenter: In a few years, the number of low-code, no-code applications
56:12 Presenter: with the growth that we’re seeing here,
56:15 Presenter: it’s just going to be so much more than what professional developers can make.
56:19 Presenter: And of course, again, I’ll put a caveat here
56:21 Presenter: that these are different types of applications,
56:24 Presenter: different scale, different complexity.
56:27 Presenter: But the need to secure those applications,
56:29 Presenter: to bring them under the professional, the security umbrella is now.
56:33 Presenter: Because businesses are going to use this.
56:37 Presenter: technology that empowers business users,
56:39 Presenter: we should be pushing for this to be adopted
56:43 Presenter: by our organizations because this could also have,
56:45 Presenter: allow us to gain better visibility than we ever had
56:50 Presenter: to what business users are doing
56:51 Presenter: and to bring them under the security umbrella.
56:54 Presenter: So go to your organization, create those,
56:57 Presenter: expand the application security frameworks
56:59 Presenter: that you have to cover low code, no code.
57:02 Presenter: Look into a low-code SDLC and try to figure out
57:07 Presenter: that local developers achieve the same level
57:11 Presenter: of security guarantees that you have
57:12 Presenter: for application security.
57:14 Presenter: Create approved use cases for low code.
57:16 Presenter: Create guidelines for business users.
57:19 Presenter: Join the OWASP top 10.
57:20 Presenter: And of course, reach out to me and let’s have a chat.
57:25 Presenter: This was very fun.
57:28 Presenter: Thank you everyone for being here.
57:30 Presenter: I’m going to, we have something like two minutes left.
57:33 Presenter: So I think we’re going to try and answer
57:37 Presenter: as we can, but I’ll be happy to answer other questions
57:42 Presenter: after the talk as well.
57:45 Presenter: One thing that, one question that I’m seeing here is that
57:50 Presenter: a lot of the examples were about Office 365
57:53 Presenter: and now we’re seeing different similar issues
57:55 Presenter: across a large variety of local, local platform.
58:00 Presenter: So the answer is unequivocally yes.
58:07 Presenter: problems with Salesforce and with ServiceNow and Workato and Zapier and Appian and OutSystems,
58:13 Presenter: the OS group is much larger than just a nitpicking on Microsoft like I’ve kind of done on this stuff.
58:37 Presenter: I’m seeing here a question about the most important security issue that an organization needs to protect from.
58:43 Presenter: So the OS top 10 tries to be, we try to make it in a way that it’s prioritized, that the risks are prioritized.
58:50 Presenter: But of course, it really depends on your organization.
58:52 Presenter: So it really, the really important thing is for you to figure out as an organization,
58:58 Presenter: where does your security appetite, where does your risk appetite lay and where you should focus.
59:07 Presenter: So that’s kind of a question that needs a lot of context from your side.
59:11 Presenter: We are kind of – we’re out of time, unfortunately, even though I see a lot of other questions.
59:16 Presenter: I will try to reach out by text and answer all of them.
59:19 Presenter: And please, if you have more questions, if you want to learn more, please reach out to me.
59:24 Presenter: I’d be happy to chat.
59:26 Presenter: Thank you very much for your time.
59:27 Presenter: And thank you, RSA, for having me.
59:31 Presenter: Yes, Michael, thank you so much for joining us.
59:34 Presenter: What a fantastic presentation.
59:37 Presenter: joining us today. To find products and solutions related to DevSecOps and application security,
59:42 Presenter: we invite you to visit rsaconference.com forward slash marketplace. Here you’ll find an entire
59:48 Presenter: ecosystem of cybersecurity vendors and service providers who can assist with your specific
59:52 Presenter: needs. Please keep the conversation going on your social channels using the hashtag
59:58 Presenter: RSAC and be sure to connect with Michael on his social channels as well. Thank you.