All talks

RSAC 365 · 2023/01

OWASP Top 10 Security Risks for Low-code/No-code

Loading presentation…

Read the abstract and transcript

Abstract

Discover what extensive research has revealed on the security of low-code/no-code applications based on scanning over 100,000 applications across hundreds of enterprise environments. Join guest speaker Michael Bargury, Co-Founder and CTO of Zenity, as he introduces the new OWASP Top 10 list, demonstrates how most applications get an identity, and shares a wide range of security issues and their backstories found in real-world environments.

Official conference abstract

Transcript

AI generated from recording.

Introduction and Context; Low‑Code/No‑Code Landscape; Growth and Pervasiveness; Low‑Code SDLC Overview

00:00 Presenter: Happy New Year to everyone. I’m your host, Kasey Zirkus, Content Strategist for RSA Conference. Thank you so much for joining us today. Our guest is Michael Bargery and he will be talking about OWASP Top 10 Risks for Low-code, No-code. Just so that you know, a reminder to our audience, all participants will be in listen-only mode. Michael will be taking questions, so if you have a question, please submit it through the Q&A feature on your screen.

00:30 Presenter: Please note that this is not a live chat.

00:33 Presenter: It’s just an inbound question that goes directly to Michael.

00:37 Presenter: As a reminder, this webcast is being recorded, and following the webcast, you’ll receive an email containing the link to the video replay.

00:44 Presenter: The replay, along with the slides, will be posted on rsaconference.com.

00:49 Presenter: Also, I’m pleased to remind you that as part of our RSAC 365 Cybersecurity Learning Program, we accept submissions on any topic year-round.

01:00 Presenter: expertise on a webcast, podcast, seminar, or blog by visiting rsaconference.com forward slash

01:06 Presenter: become a contributor. I now invite Michael to introduce himself and dive right into today’s

01:12 Presenter: topic. Michael, over to you. Thank you, Casey. Hi, everyone. Excited to be here. My name is Michael

01:21 Presenter: and we’ll be spending the next hour or so together. So let me kind of start with a

01:28 Presenter: brief introduction. This talk is going to be interesting because the subject of this talk,

01:34 Presenter: focusing on low-code, low-code, is really an underexplored area with security. I’ve been in

01:40 Presenter: this space for three to four years now, working around the intersection of low-code and security.

01:47 Presenter: About two years ago, I co-founded Xenity, which is a company focused on this space, and a lot of my

01:53 Presenter: observations come from this company.

01:55 Presenter: I’ve spent several years at Microsoft as part of the CTO office for

02:00 Presenter: Azure security where I spent time working with our top customers to try and

02:07 Presenter: address large problems like IoT, cloud, and confidential computing.

02:13 Presenter: I also lead an OWASP group that is dedicated to low code, no code.

02:18 Presenter: And this OWASP group is far bigger than myself.

02:22 Presenter: as we move forward, this talk is going to be focused

02:26 Presenter: on the main thing that we’ve been working on,

02:28 Presenter: which is finding and categorizing

02:31 Presenter: those top 10 risks for low code.

02:33 Presenter: I also write about low code, no code security

02:36 Presenter: and dark reading.

02:37 Presenter: If there’s anything you’re interested in this talk,

02:40 Presenter: if you find this kind of thing resonating with you,

02:43 Presenter: please reach out.

02:45 Presenter: We are always looking for collaborators.

02:50 Presenter: So here’s what we’re going to do today.

02:53 Presenter: We’re gonna start with understanding

02:55 Presenter: just how pervasive low code, no code is.

02:58 Presenter: So how wide is it being used across the industry?

03:01 Presenter: We’re going to see how low code, no code grows

03:04 Presenter: or how did it grow?

03:06 Presenter: How did we get to where we are today?

03:09 Presenter: Later on, we’re going to dive into the low code SDLC

03:12 Presenter: and understand fundamentally what are the challenges

03:17 Presenter: and after that we dive into the Diorus top 10,

03:20 Presenter: understand with concrete real world issues,

03:24 Presenter: why real world examples,

03:26 Presenter: why are these things so important?

03:31 Presenter: And so without further ado,

03:34 Presenter: I’m going to start with how pervasive low code, no code is.

03:38 Presenter: And the next slide that I’m going to show

03:41 Presenter: is probably the most important slide in the entire talk.

03:44 Presenter: And that is because this slide is going to show us

03:50 Presenter: how fast low code, no code grows

03:54 Presenter: and how significantly different it is

03:56 Presenter: in terms of scale from what we’ve been used to.

04:00 Presenter: This chart right here shows you anonymized statistics

04:03 Presenter: that represent a single Fortune 500 customer

04:07 Presenter: and then a single Fortune 500 company

04:10 Presenter: and the number of applications,

04:12 Presenter: low-code, no-code applications

04:14 Presenter: that they have over multiple years.

04:17 Presenter: And you can see the exponential growth

04:19 Presenter: in the number of applications.

04:21 Presenter: Now, of course, the definition of application

04:23 Presenter: is really important here, right?

04:25 Presenter: Application could be something very large,

04:27 Presenter: but it could also be a micro-application

04:29 Presenter: doing a single kind of a process.

04:32 Presenter: And here you get a whole bunch of those.

04:35 Presenter: So with those large numbers,

04:36 Presenter: some of these applications would be very small

04:43 Presenter: and other applications would be huge.

04:45 Presenter: This also means that these are not applications

04:48 Presenter: that are only getting built by IT.

04:51 Presenter: With such large numbers, most of these applications

04:55 Presenter: are actually being built by business teams.

04:57 Presenter: And this is why this matters.

04:59 Presenter: It matters both in terms of the number of applications

05:02 Presenter: that are being built.

05:03 Presenter: Of course, manual reviews are out of the question.

05:06 Presenter: of numbers, but it’s also important in terms of who’s building those applications.

05:11 Presenter: This chart right here is the reason why this is so important for us to tackle this.

05:16 Presenter: Because as the sooner we get on bringing low code,

05:21 Presenter: no code under the security umbrella, the better we’ll be left off.

05:28 Presenter: So now that we understand why low code, no code, or why now that we have kind of a

05:32 Presenter: feeling of why low code, no code is something that we need to focus on.

05:36 Presenter: what low-code and no-code is exactly,

05:38 Presenter: and how do we get to where we are?

05:41 Presenter: So this slide tries to capture basically

05:44 Presenter: the reason behind low-code and no-code.

05:46 Presenter: Why does low-code and no-code exist?

05:48 Presenter: Of course, there’s the perennial problem

05:50 Presenter: of resource shortage, right?

05:54 Presenter: The business needs much more than IT is able to provide,

05:57 Presenter: and we’ve all felt this ourselves,

Risk Framework Introduction

05:59 Presenter: and we see other people feeling it

06:01 Presenter: throughout the business all of the time.

06:03 Presenter: Now, when we see that these kind of, as a business user, of course, the frustration of waiting for IT is something that people are used to.

06:14 Presenter: And people have been trying to find ways to get business users to build their own things, to solve their own problems for a long time, right?

06:25 Presenter: If this sounds familiar, the entire concept of empowering business users, it’s because it is.

06:32 Presenter: We’ve been trying throughout the history to put more power in the hands of business users for a long time now,

06:39 Presenter: from application generators to Visual Basic to Excel to things that are about helping business users address their own needs.

06:49 Presenter: And low-code, no-code is, of course, just another step in this trend of IT decentralization,

06:56 Presenter: providing the ability for business users to solve their own problems.

06:59 Presenter: Now, of course, with these kind of technologies, we also know what happened with them on the

07:05 Presenter: other side.

07:06 Presenter: So we also know that everything that we put out there for business users to use can also

07:11 Presenter: be abused by malicious intent.

07:14 Presenter: And so here are a few examples of what people are building

07:20 Presenter: with low code, no code.

07:21 Presenter: So it could be if small automation.

07:26 Presenter: So for example, every time I get an email,

07:28 Presenter: do something with that email.

07:30 Presenter: So for example, look for specific emails

07:32 Presenter: and store their attachments somewhere.

07:34 Presenter: It could be integration.

07:36 Presenter: So you could have a business application

07:37 Presenter: or business integration team within IT

07:39 Presenter: that is connecting together the various parts of the enterprise.

07:44 Presenter: It could be business applications that are used for internal or external operations.

07:48 Presenter: It could be entire products, entire products built with no-code, no-code, mobile apps.

07:52 Presenter: You’re seeing on screen a bunch of examples,

07:55 Presenter: but shortly I will share a few concrete examples from organizations that we’ve been working with.

08:01 Presenter: By the way, I’m getting a question.

08:03 Presenter: I’m seeing a question in the Q&A asking about the numbers that we saw earlier

08:09 Presenter: everything that you’re going to see in these slides today

08:14 Presenter: is coming from anonymized statistics

08:16 Presenter: that were either shared by organizations

08:18 Presenter: that are part of the OWASP group,

08:20 Presenter: or that were shared,

08:22 Presenter: or they are part of kind of applications

08:25 Presenter: that they have looked at.

08:26 Presenter: So together with the entire OWASP group,

08:30 Presenter: this is a culmination of scanning

08:32 Presenter: more than 100,000 different applications

08:34 Presenter: across multiple organizations.

08:39 Presenter: That’s where all of the information is going to come today.

08:44 Presenter: So we understand, so this is kind of a high level of what people are building.

08:50 Presenter: But actually, one of the questions is basically,

08:54 Presenter: you’re seeing that I’m talking here both about business applications,

08:58 Presenter: professional developers, and about business users.

09:01 Presenter: So everybody in the enterprise is also called citizen developers.

09:05 Presenter: One of the interesting things to understand is how do these technologies find their way into the enterprise?

09:12 Presenter: So how does the typical enterprise end up with low-code, no-code applications being used, being developed by their business users?

09:20 Presenter: And one of the key things to note is that this is really not a choice.

OWASP Top 10 Risks for Low‑Code/No‑Code

09:25 Presenter: The vendors that you see out there on the screen, you can kind of, I’m sure you’ll find one of them at least that most of the organizations

09:36 Presenter: because every SAS vendor today is actually becoming

09:40 Presenter: a low-code, no-code platform.

09:42 Presenter: And there’s a clear reason for that, right?

09:45 Presenter: It’s about extendability, it’s about becoming a platform

09:47 Presenter: rather than a single solution.

09:50 Presenter: So if you think about Salesforce,

09:52 Presenter: it’s far more than a CRM.

09:54 Presenter: It’s a new type of way to build applications,

09:57 Presenter: very similar to the public cloud.

09:59 Presenter: And so when organizations find them,

10:02 Presenter: so as a large organization,

10:05 Presenter: a customer of either Microsoft or Salesforce or ServiceNow

10:08 Presenter: or any other one of the companies that you’re seeing

10:11 Presenter: or Screen or others,

10:12 Presenter: these companies are introducing low-code, no-code capabilities

10:16 Presenter: into their products.

10:17 Presenter: And so low-code, no-code is finding its way

10:20 Presenter: directly into the heart of the enterprise.

10:23 Presenter: And the important thing is that it’s built directly

10:26 Presenter: on top of business data,

10:27 Presenter: because of course, business-sensitive data

10:29 Presenter: sits within each one of these platforms.

10:31 Presenter: And that’s why every enterprise today

10:35 Presenter: according to the statistics that we’ve been able to collect,

10:39 Presenter: with at least five to seven different

10:40 Presenter: low-code, no-code platforms,

10:42 Presenter: and we’re talking about large low-code, low-code platform,

10:45 Presenter: not just the ones that are kind of

10:47 Presenter: a part of a single SaaS solution,

10:49 Presenter: but full-blown platforms that allow developers,

10:53 Presenter: allow business users to build

10:54 Presenter: their own applications and automations.

10:56 Presenter: And so the entire promise around low-code, no-code,

11:01 Presenter: basically comes down to,

11:05 Presenter: we’re trying to basically bring you the key points

11:08 Presenter: behind the promise of low-code, no-code.

11:11 Presenter: First of all, it’s just that the idea

11:14 Presenter: is to accelerate development.

11:16 Presenter: And by accelerating development,

11:18 Presenter: it starts with professional development teams,

11:22 Presenter: putting more power in the hands of developers

11:25 Presenter: and expediting their way to actually get into value.

11:30 Presenter: And it continues with actual business users

11:35 Presenter: to those business users.

11:36 Presenter: And you can see that low code, no code addresses for you

11:40 Presenter: a large number of features that are really,

11:44 Presenter: they’re really complex.

11:45 Presenter: So if you want to, so covering authentication

11:49 Presenter: and authorization, connectors across SAS and on-prem,

11:54 Presenter: development lifecycle, these are things that are important

11:58 Presenter: and are also difficult to get right.

12:02 Presenter: And so low code, no code has a huge promise.

12:05 Presenter: why people are actually using it.

12:08 Presenter: So before we move forward with looking at issues

12:12 Presenter: with low-code, no-code, I think it’s really clear,

12:14 Presenter: it’s really important for all of us to have

12:16 Presenter: a clear example in mind, a clear application

12:21 Presenter: we can think of when we’re thinking about

12:23 Presenter: low-code, no-code applications.

12:25 Presenter: Because one of the things that I’m sure

12:26 Presenter: you’re asking yourself right now is

12:29 Presenter: how critical those applications are.

12:31 Presenter: So when business users are building their applications,

12:35 Presenter: business critical or are they building applications

12:37 Presenter: that are specific to their own needs?

12:40 Presenter: And we’ll see in a moment that business users

12:42 Presenter: are for sure building applications

12:44 Presenter: that can be business critical,

12:46 Presenter: that can be important for the business to operate.

12:50 Presenter: Here’s one example.

12:51 Presenter: So this example actually comes from Microsoft.

12:55 Presenter: So when you visit Microsoft offices physically

13:00 Presenter: and you need to provide your COVID vaccination proof,

13:05 Presenter: is with the low code application,

13:07 Presenter: built with something called portal apps,

13:09 Presenter: part of Power Platform, the local local platform.

13:12 Presenter: And you can see that this application basically allow,

13:16 Presenter: asks you to fill out the form

13:18 Presenter: and upload your vaccine certificate.

13:20 Presenter: Now, of course, this is very sensitive information.

13:24 Presenter: And the way that this information is being stored,

13:26 Presenter: the way that the information is being handled

13:28 Presenter: is very important for Microsoft’s promise.

13:32 Presenter: And so even though it’s built with low-code capabilities, it’s still a very crucial application with critical health data that should be addressed accordingly.

13:45 Presenter: Here’s another example.

13:46 Presenter: This one comes from a use case for Workato.

13:50 Presenter: Workato is an automation platform.

13:52 Presenter: And this example actually comes from Slack

13:55 Presenter: where they automated their entire order to cache processes

14:00 Presenter: with a no code interface.

14:04 Presenter: So this of course is a very important process

14:08 Presenter: and we’re talking about tens of different automations

14:11 Presenter: that are combined together putting information

14:13 Presenter: from multiple different sources.

14:15 Presenter: You can see this can become very, very complex.

14:18 Presenter: And so of course,

14:19 Presenter: And of course, this is very important to get right.

14:22 Presenter: Now, the next example I’m going to show you is going to be a bit different,

14:26 Presenter: and you’ll soon find why.

14:30 Presenter: In this example, this is a story where a team within Microsoft,

14:36 Presenter: actually within the marketing department within Microsoft,

14:39 Presenter: that team was in charge of basically coordinating product releases for lunches

14:45 Presenter: and for conferences.

14:46 Presenter: And they found that they have different processes that are put in place in order to release, to do product releases.

14:53 Presenter: And each product group or each group had different processes and they wanted to streamline it.

15:00 Presenter: So the folks from those teams, again, business users, they created an application that was actually basically a way for them to enforce that process or to streamline that process across all of the teams that they were connecting to.

15:19 Presenter: This took them two days to implement as business users.

15:24 Presenter: And this became the golden standard at Microsoft for this process of optimizing, of kind of going through product launches.

15:36 Presenter: And so this is something that started with a few people that wanted to streamline their own work.

15:41 Presenter: and it ended up as the go-to application to manage product launches

15:47 Presenter: or marketing launches that is used, as you can see on screen,

15:50 Presenter: with 150 different employees across the company.

15:54 Presenter: This is actually taken from Microsoft website.

15:56 Presenter: You can see the link below.

15:58 Presenter: And, of course, and you can see that very shortly,

16:01 Presenter: this became like the go-to standard.

16:04 Presenter: This is something that is built by business users.

16:07 Presenter: And so part of why this example is important is because it represents a shift,

16:16 Presenter: a shift where low-code stops being only tools that professional developers can use

Concrete Examples and Case Studies

16:25 Presenter: and becomes something that business users can use as well to build their own needs.

16:31 Presenter: And that’s a huge gap.

16:33 Presenter: So the next thing I want to show you is to try and figure out when this happened.

16:39 Presenter: When did low-code, no-code become something that is trying to empower business users

16:44 Presenter: rather to make professional development teams more productive?

16:50 Presenter: And so we’ll do that by looking through the lens of Microsoft,

16:55 Presenter: simply because they’re a leader in this space,

16:59 Presenter: and they’ve also shared a lot of their thought leadership throughout the years.

17:03 Presenter: Here’s a quote from Satya Nadella’s speech

17:06 Presenter: at Microsoft Build 2018.

17:09 Presenter: This is where he’s talking about Power Platform

17:12 Presenter: for the first time.

17:13 Presenter: Power Platform is their local, local platform.

17:15 Presenter: And you can see that he’s talking about it

17:17 Presenter: as an extendability framework for dynamics.

17:20 Presenter: This is basically Microsoft’s response to everything.

17:25 Presenter: So this is very similar to what Salesforce has around

17:29 Presenter: customizing your Salesforce instance.

17:33 Presenter: There are partners that help you customize your dynamics

17:38 Presenter: or your Salesforce to fit your organization.

17:40 Presenter: And this is described as a tool for them to be productive.

17:44 Presenter: So Salesforce, for example, has Apex code,

17:46 Presenter: there’s Java integrations.

17:47 Presenter: Today there are also local no-code tools,

17:49 Presenter: we’ll get to that later.

17:51 Presenter: The same thing applies here.

17:52 Presenter: So Microsoft is basically trying to say,

17:54 Presenter: hey, the entire ecosystem around dynamics,

17:58 Presenter: you can now use local no-code capabilities

18:01 Presenter: to accelerate your work.

18:03 Presenter: instead of building things only with .NET extensions.

18:07 Presenter: Let’s see another quote from Satya a year later.

18:11 Presenter: This one, again, a year later,

18:14 Presenter: is a completely different message.

18:16 Presenter: You can see that this shift has,

18:18 Presenter: that there’s a shift in focus

18:19 Presenter: from professional developers to citizen developers,

18:23 Presenter: which is the way that Microsoft calls it.

18:26 Presenter: Now the entire industry is calling business users

18:28 Presenter: that are developing application.

18:30 Presenter: and you can see that there is a clue here to why did they make the shift

18:36 Presenter: and that clue is that two and a half million citizen developers

18:39 Presenter: already using Power Platform.

18:41 Presenter: So, of course, the number of business users is far larger

18:44 Presenter: than the number of professional developers.

18:47 Presenter: And so, of course, it makes total sense for vendors

18:51 Presenter: to try and open up the market of users that can use those platforms

18:57 Presenter: because it can also provide a lot of value for companies.

19:00 Presenter: You can also see in the second quote,

19:02 Presenter: why this is so important.

19:04 Presenter: This explains the shift.

19:06 Presenter: Microsoft is looking at this as the new Excel,

19:08 Presenter: the new way to provide business users,

19:12 Presenter: to empower business users,

19:14 Presenter: to actually solve their own needs.

19:16 Presenter: And this is far larger than Microsoft now.

19:18 Presenter: We’re seeing this across the industry.

19:21 Presenter: This is a very large shift to make in one year.

19:25 Presenter: And it also shows us

19:27 Presenter: kind of the way that low-code got from one place to another,

19:31 Presenter: from targeting only professional developers

19:33 Presenter: to targeting business users as well.

19:36 Presenter: Three years later, this is a quote from last year,

19:40 Presenter: from Satya, you can see that Microsoft already has

19:43 Presenter: 20 million active users using their low-code,

19:46 Presenter: low-code platform.

19:46 Presenter: So a 10x growth, about a 10x growth in three years.

19:50 Presenter: And again, this just shows you how successful

19:54 Presenter: this technology here is,

19:57 Presenter: to different organizations.

20:00 Presenter: This was all looking through the Microsoft Lens,

20:03 Presenter: but this is actually a story about the entire industry.

20:05 Presenter: So we can see Salesforce doing the same,

20:08 Presenter: ServiceNow are talking about in the same message,

20:10 Presenter: WorkCarto is doing the same.

20:12 Presenter: Other vendors are looking to expand

20:14 Presenter: beyond professional development to business users as well.

20:19 Presenter: And so before we move forward,

20:21 Presenter: it’s really important that we understand

20:23 Presenter: just how easy it is to create those applications,

20:27 Presenter: this is crucial for us, for you to trust me

20:30 Presenter: that this is actually something

20:31 Presenter: that business users can actually build.

20:33 Presenter: And so let me show you an example.

20:36 Presenter: And this is going to be kind of a very quick example,

20:40 Presenter: what I’ll show here,

20:43 Presenter: and you’ll see the video in a moment.

20:47 Presenter: Okay, so what I’m going to show you

20:51 Presenter: is a very kind of simple example.

20:54 Presenter: Basically, my organization is using Slack,

Summary, Takeaways, and Q&A — Part 1

20:57 Presenter: And one of the things that happens in Slack is that people mention you on a public channel,

21:03 Presenter: and they expect a response pretty quickly.

21:06 Presenter: And so kind of as a joke, I wanted to create an application that allowed me to basically appear as if I’m on a call.

21:14 Presenter: So this automation that I’m creating right now is every time that somebody mentions me on a Slack channel,

21:22 Presenter: the automation is going to trigger.

21:25 Presenter: It’s going to change my status as if I’m on a call with a call status,

21:30 Presenter: with a call logo.

21:31 Presenter: And then it’s going to wait for like five minutes,

21:34 Presenter: and then it will change my status again as if I’m active.

21:38 Presenter: Now, of course, this is a joke,

21:39 Presenter: but you can see how quickly I can build this thing.

21:43 Presenter: So while I’m talking to you, this thing gets built.

21:45 Presenter: And just think about the number of things that Zapier had to handle

21:51 Presenter: for this thing to work.

21:52 Presenter: And by the way, right now you’re seeing the publish button.

21:55 Presenter: This publish button is basically a combined button

21:58 Presenter: that does two things.

22:00 Presenter: One is save and the other is deployed to production,

22:02 Presenter: which is kind of interesting.

22:04 Presenter: And so again, let’s think about all of the things

22:07 Presenter: that Zapier had to handle in order for these things

22:10 Presenter: to work.

22:11 Presenter: So there’s authentication to Slack that needs to work here.

22:16 Presenter: There’s a secret, right?

22:17 Presenter: Because my identity is there somewhere

22:19 Presenter: in order to connect to Slack.

22:20 Presenter: You need to subscribe to Webhook.

22:22 Presenter: You need to support APIs and the different changes

22:25 Presenter: You need to be able to delay for five minutes

22:28 Presenter: or something need to operate behind the scenes.

22:31 Presenter: There’s a, this is a significant piece of software.

22:35 Presenter: It’s not just like a small script that somebody created

22:39 Presenter: and it’s all being built with no code.

22:41 Presenter: It’s all being built with drag and drop

22:43 Presenter: without really understanding what’s going on behind it.

22:47 Presenter: And again, the most important thing here to think about

22:50 Presenter: when we’re thinking in a security perspective

22:52 Presenter: is the identity.

22:53 Presenter: How does this application run?

22:55 Presenter: How does it connect to Slack?

22:57 Presenter: If I’m going to look from the logs, from Slack’s logs,

23:01 Presenter: what’s actually going on here?

23:02 Presenter: What’s happening?

23:03 Presenter: And so we’ll bring down to it in a minute,

23:06 Presenter: but just not to keep you hanging,

23:08 Presenter: this is running with my own identity.

23:10 Presenter: So this is running as if I have done it myself.

23:14 Presenter: And that’s kind of the crucial piece here.

23:17 Presenter: And so now that we understand

23:21 Presenter: how easy it is to create low-code, no-code applications.

23:24 Presenter: Let me try and switch back to the deck.

23:32 Presenter: Okay, so now that we understand just how easy it is

23:35 Presenter: to connect to, to create those applications,

23:40 Presenter: the next thing I want to kind of discuss is,

23:43 Presenter: I mean, we understand how easy it is

23:45 Presenter: to create those applications.

23:46 Presenter: We’ve also seen the huge growth in numbers.

23:51 Presenter: What I’m trying to capture here is the fact that there is a culmination of three different things that are happening at the same time.

24:01 Presenter: One is that major vendors across the industry have a strong incentive to grow the number of users that are using their platforms

24:10 Presenter: and to expand the value that they can provide across the industry.

24:16 Presenter: that by targeting business users, by empowering business users. These are vendors that are

24:21 Presenter: already inside organizations, so there’s no choice. There’s no choice on whether or not

24:26 Presenter: this will happen in your organization. It’s going to happen. The question is, how soon will you get

24:31 Presenter: on top of it? The second point is that companies are actually looking for this. So companies are

24:38 Presenter: lacking IT resources, companies are looking to do digital transformation. This is a way to

24:46 Presenter: to actually solve their own problems.

24:48 Presenter: And so this is a really cool piece of technology

24:50 Presenter: that could provide a lot of business value.

24:52 Presenter: And the third piece here is that unlike previous attempts

24:56 Presenter: to try and actually put more power

24:59 Presenter: in the hands of business users,

25:00 Presenter: this is actually working.

25:02 Presenter: So this is achievable for business users

25:05 Presenter: that are not development professionals

25:09 Presenter: to build their own applications.

25:11 Presenter: And that’s why it’s important

25:13 Presenter: to address low-code, no-code right now.

25:18 Presenter: So now that we understand what no code, no code is,

25:21 Presenter: and how did we get here,

25:23 Presenter: the last thing I want to tackle

25:25 Presenter: before I go into concrete risks

25:28 Presenter: is how these applications get developed.

25:30 Presenter: So how does the SDLC look like for low code, no code?

25:34 Presenter: This is a kind of a traditional low code,

25:37 Presenter: this is a traditional SDLC,

25:38 Presenter: nothing low code, no code specific about it.

25:41 Presenter: So I’ll kind of skip directly through it.

25:44 Presenter: This is my attempt to try and say, okay, who’s in charge of each one of those things?

25:48 Presenter: Now, of course, this will change between different organizations, between different types of applications.

25:54 Presenter: But kind of in a high level, the business is in charge of basically putting the need out there.

26:00 Presenter: Engineering is in charge of creating it, planning it and creating it.

26:04 Presenter: There might or might not be QA as a separate discipline.

26:09 Presenter: And there’s also kind of deployment, monitoring, production.

26:14 Presenter: those things that are about making sure

26:15 Presenter: that the applications are actually operating as expected.

26:19 Presenter: The only reason that I pointed this out there,

26:21 Presenter: because of course these things are,

26:23 Presenter: this is kind of trivial,

26:25 Presenter: is to try and distinguish how low-code, no-code looks

26:28 Presenter: next to this SDLC.

26:34 Presenter: And this is kind of the key point

26:37 Presenter: about how low-code, no-code gets created.

26:40 Presenter: Now, what I’m basically saying here is that the business

26:44 Presenter: or the person who’s creating the application

26:46 Presenter: can do everything in the SDLC.

26:49 Presenter: This of course is one side of the spectrum.

26:54 Presenter: On the other side of the spectrum,

26:56 Presenter: there are professional development teams using SDLC

26:59 Presenter: as you would expect with professional development.

27:03 Presenter: And so this happens as well,

27:04 Presenter: but the entire spectrum is out there.

27:06 Presenter: We’re also seeing developers that are using low code, no code

27:11 Presenter: with this kind of hit save to deploy changes approach

27:15 Presenter: where there’s not kind of any official planning

27:18 Presenter: or any official QA or verification.

27:22 Presenter: So it’s not that, so some teams are doing it,

27:26 Presenter: but there’s nothing, but it’s very difficult

27:29 Presenter: to enforce them to do it.

27:31 Presenter: And one of the things that we’re seeing again and again

27:33 Presenter: is that the tools around applying SDLC,

27:37 Presenter: true SDLC to low-code, non-code, they’re really lacking.

27:41 Presenter: are trying their best to apply the lessons learned

27:43 Presenter: from professional development to development

27:46 Presenter: with low code, no code, they’re finding it challenging

27:48 Presenter: because there’s no code to scan,

27:50 Presenter: there’s no easy way to plug into CICD in many cases,

27:55 Presenter: there’s no one time monitoring.

Summary, Takeaways, and Q&A — Part 2

27:57 Presenter: So, and again, this depends,

27:59 Presenter: it’s very difficult to discuss these topics

28:02 Presenter: across different platforms

28:03 Presenter: because every platform would be different

28:05 Presenter: and some platforms are having a more mature SDLC than others,

28:11 Presenter: In general, SDLC for low-code, no-code is far more immature than the professional development SDLC.

28:20 Presenter: And this is also at the root of two things.

28:26 Presenter: One is at the root of many security issues that we’ll find that we’ll see in a moment.

28:31 Presenter: And the other side is that this is also at the root of why low-code, no-code is so successful,

28:35 Presenter: because it allows you to do things quickly.

28:38 Presenter: There is one stakeholder that can do everything from thinking about the need to solving the need for their own.

28:45 Presenter: And so one thing that you might be thinking right now when I’m talking about these kind of issues is who’s in charge?

28:53 Presenter: Who needs to own the risk that is being created by local local applications?

28:59 Presenter: And you might be tempted to think that the people that are in charge here should be the platforms themselves.

29:04 Presenter: So the people that have put this platform,

29:06 Presenter: that are creating the local, local platforms,

29:09 Presenter: and they should be in charge of the applications

29:11 Presenter: that are being created by those platforms.

29:14 Presenter: Or in other words, you could be thinking,

29:16 Presenter: hey, why don’t the platform vendors make sure

29:20 Presenter: that every application created by their platform is secure?

29:24 Presenter: Now, this, we’ve actually learned,

29:27 Presenter: we’ve actually tried this before, and this failed,

29:30 Presenter: and we’ve come across a better solution.

29:33 Presenter: This is the same shared responsibility model that we’ve seen in the public cloud.

29:39 Presenter: So when the public cloud started, it took us as an industry some time to figure out that basically,

29:46 Presenter: while the public cloud is, while AWS, GCP, Azure, they are in charge of making sure the platform itself is secure

29:57 Presenter: and that the building blocks are secure.

29:59 Presenter: Of course, as an organization that builds something in the cloud,

30:02 Presenter: we’re in charge of what we’re building.

30:04 Presenter: There’s no other way.

30:05 Presenter: If you’re building something, you are in charge of the business logic.

30:09 Presenter: You understand what is feasible for your organization or not.

30:12 Presenter: The vendors, they’re in charge of putting the building blocks for you,

30:15 Presenter: but you’re all in charge of what you’re creating.

30:17 Presenter: And this is the same thing for low code, no code.

30:19 Presenter: And so the OWASP top 10 risks for low code, no code,

30:24 Presenter: focus on the customer’s side of the shared responsibility model.

30:29 Presenter: rather than the platform.

30:30 Presenter: Of course, we need to push the platforms

30:35 Presenter: to own their part as well.

30:37 Presenter: And actually most platforms are doing it pretty well

30:40 Presenter: from my perspective.

30:42 Presenter: But the part where we need to own the applications

30:46 Presenter: that we’re building, this is what’s missing.

30:48 Presenter: And this is what the OWASP Top 10 is focused on.

30:54 Presenter: And so without further ado,

30:57 Presenter: we’re going to talk about the OWASP top 10 risk for low-code, no-code.

31:01 Presenter: And before I show you the concrete list, I’m going to say that,

31:06 Presenter: I’m going to share that there are basically two goals for my talk today.

31:10 Presenter: One goal is just to spread this information out there and

31:14 Presenter: to help the entire industry grow our understanding of this space.

31:19 Presenter: And the second piece is that we want more people involved in the low-code, no-code group.

31:22 Presenter: So there are already people joining us

31:25 Presenter: from across the industry, from Microsoft and Palo Alto

31:28 Presenter: and other large and small companies as well.

31:32 Presenter: Vendors, people that are using low code, no code

31:35 Presenter: to build their own applications.

31:37 Presenter: The larger perspective we’ll have on this problem,

31:40 Presenter: the better.

31:41 Presenter: And so the list that you’re going to see today

31:44 Presenter: is a result of the scan of more than 100,000

31:50 Presenter: different low code, no code applications

31:52 Presenter: earlier across the industry, across different local,

31:56 Presenter: local platforms, and that was the basis

31:59 Presenter: of finding out those problems,

32:02 Presenter: of finding out what are the problems

32:03 Presenter: that we see with local, local, and then the group,

32:07 Presenter: and then the group debated on categories

32:09 Presenter: and then thinking about how do we separate this

32:12 Presenter: into categories that make sense.

32:14 Presenter: And we’d be, if you’re interested in kind of,

32:17 Presenter: in joining the group, in getting information,

32:20 Presenter: getting kind of access to information behind it

32:23 Presenter: in contributing yourself,

32:24 Presenter: please reach out to me after this talk.

32:29 Presenter: And so these are the top 10 for low code, no code,

32:32 Presenter: and we’re going to go through each one.

32:34 Presenter: So that’s kind of the next step.

32:42 Presenter: Okay.

32:45 Presenter: We’ll start with the first thing,

32:47 Presenter: which is account impersonation.

32:50 Presenter: that we saw when I created this API example

32:52 Presenter: is that identity was really not part

32:55 Presenter: of what I had to do there.

32:57 Presenter: It was kind of implicit.

32:58 Presenter: Now, when you think,

33:00 Presenter: think kind of as a low code, no code platform,

33:03 Presenter: when you want to expand within an organization,

33:07 Presenter: you want people to adopt your platform

33:08 Presenter: and to build a lot of application with it.

33:11 Presenter: The number one thing that will block you

33:14 Presenter: in an enterprise is actually permissions.

33:17 Presenter: If every user, business user, would have to ask for permissions from IT to build their own application,

33:25 Presenter: before they actually build it, you won’t see the exponential growth that you saw in the graph earlier.

33:31 Presenter: So the way that this gets circumvented is that business users can embed their own identities within application,

33:38 Presenter: of course, not just business users, professional developers as well,

33:40 Presenter: and this allows the applications to be built very rapidly.

33:46 Presenter: When you get to a place where you want to build an application,

33:51 Presenter: you give that application the ability to operate on your behalf.

33:54 Presenter: And then every user of that application ends up using your identity.

33:58 Presenter: Let’s see an example.

34:00 Presenter: So, and this is a real example.

34:02 Presenter: So this is a customer care team from a large e-commerce company.

34:06 Presenter: They basically had a problem where people that were involved in support cases for customers

34:12 Presenter: didn’t have the entire context about that customer.

34:14 Presenter: And they didn’t have a way to, so they wanted to share the information that they had about the customer with people relevant to the case.

34:22 Presenter: They created an application that allowed, that basically used the customer care team identity to fetch information from the database behind it.

34:34 Presenter: And every employee that had a relation to some case, to some support case, was able to see information about relevant customers.

34:44 Presenter: employees only having the ability to view information

34:47 Presenter: about customer cases that they are related to.

34:50 Presenter: So it seems like everything’s fine, right?

Summary, Takeaways, and Q&A — Part 3

34:53 Presenter: Permissions are being granted kind of in the right way.

35:00 Presenter: So it seems like the problem is solved.

35:03 Presenter: Employees are happy because they are able

35:05 Presenter: to address customer needs better.

35:07 Presenter: Customers are happy because their tickets

35:09 Presenter: get answered better.

35:10 Presenter: And the customer care team is happy because, well,

35:15 Presenter: in an easier way across the organization.

35:18 Presenter: What’s the problem here?

35:21 Presenter: Well, of course, imagine this from the SOX perspective.

35:24 Presenter: Imagine this from the security perspective.

35:26 Presenter: This is an application.

35:28 Presenter: A lot of people in the organization

35:30 Presenter: are using this application,

35:32 Presenter: but they are all using the same underlying identity,

35:35 Presenter: which in this case was admin credentials

35:37 Presenter: to the customer database.

35:38 Presenter: So from the SOX perspective, they get an alert,

35:41 Presenter: which looks like abnormal activity, right?

35:44 Presenter: it looks like somebody has stolen this admin credential

35:47 Presenter: and is now querying the database across the organization

35:51 Presenter: with different queries that perform

35:54 Presenter: from different IPs and hosts across time.

35:57 Presenter: And so from the SOC perspective, of course,

35:59 Presenter: this looks like a hack.

36:01 Presenter: And so what happened here was that the SOC

36:03 Presenter: started to ask around to understand.

36:06 Presenter: And the first thing that they did is to investigate

36:09 Presenter: the user that was being used.

36:11 Presenter: And that user was actually the same user

36:14 Presenter: And so once they are able to reach out to the team there,

36:18 Presenter: they figured it out, they understood what actually happened

36:21 Presenter: that the application is embedding

36:22 Presenter: the makers own identity within the app.

36:25 Presenter: And so what ended up happening as a,

36:29 Presenter: so of course the mitigation here is pretty obvious, right?

36:31 Presenter: The mitigation is that every user needs to be able

36:34 Presenter: to access the application with their own identity.

36:37 Presenter: And the underlying connections to the data

36:39 Presenter: should also be only for their own identity.

36:42 Presenter: And this is a pattern that we see again and again.

36:45 Presenter: This is not a problem only with Zapier as we saw earlier,

36:47 Presenter: it’s across different local, local platform.

36:50 Presenter: It’s actually a fundamental way in which we see

36:52 Presenter: local, local platforms accelerate and build their audience.

36:57 Presenter: And so this was kind of, and this was one example.

37:03 Presenter: Moving forward, the next category is authorization.

37:08 Presenter: Now, authorization of course is a big deal.

37:12 Presenter: Because low-code, no-code platforms are only as useful as the applications that they can access.

37:20 Presenter: Services that they can access, SaaS services, on-prem, everywhere.

37:24 Presenter: And low-code, no-code platforms have figured out ways to actually get connected to the entire organization very quickly.

37:33 Presenter: So if you open up a popular low-code, no-code platform today, you’ll typically see hundreds of integrations that are just waiting for you,

37:39 Presenter: including things that can happen,

37:41 Presenter: that can, including on-prem gateways

37:43 Presenter: or ways to fetch information

37:45 Presenter: or push information to on-prem.

37:47 Presenter: And so this leads to something that we see again,

37:53 Presenter: in multiple platforms, which is credential sharing.

37:57 Presenter: And so when you saw me create that application earlier,

38:00 Presenter: earlier with JPR, and I explained that this application

38:04 Presenter: is actually using my identity,

38:07 Presenter: one thing that happens there on top of that

38:11 Presenter: is that when I finish creating my identity,

38:15 Presenter: which actually means basically an OAuth popup window,

38:18 Presenter: I plug in my credentials and I store my refresh token.

38:21 Presenter: Now there’s a nice little share button.

38:24 Presenter: And you can see here on screen, default environments

38:28 Presenter: or notions of default environments

38:29 Presenter: across different platforms where credentials

38:32 Presenter: are being shared as a feature of the platform.

38:36 Presenter: Again, the platforms are allowing users to embed,

38:40 Presenter: to log in to a SaaS service or to a SQL server

38:44 Presenter: or to Office or to Gmail.

38:46 Presenter: And then these connections, these credentials

38:52 Presenter: can be shared with other users.

38:54 Presenter: And they can be shared explicitly.

38:57 Presenter: So just click on share and share it with somebody else.

39:02 Presenter: by embedding them within applications.

39:05 Presenter: And so low-code, non-code platforms have actually built something that is,

39:11 Presenter: as I write here in the title, credential sharing as a service.

39:16 Presenter: Now, again, there’s a reason behind it.

39:18 Presenter: This is a great accelerator for productivity.

39:25 Presenter: But, of course, the security implications are dire

39:28 Presenter: because once an attacker gets into one of those platforms,

39:32 Presenter: they already have a bag of credentials that they can leverage.

39:35 Presenter: Let me show you another example of authorization

39:39 Presenter: of using or issues with authorization.

39:43 Presenter: So one other typical anti-pattern that we see

39:46 Presenter: is that in many cases, it’s very difficult to figure out

39:50 Presenter: what are the APIs that are working

39:52 Presenter: behind a low-code application.

39:54 Presenter: And so in order to make it easier in the development phase,

39:59 Presenter: we see users doing the following thing.

40:03 Presenter: They provide all of the users of their application

40:07 Presenter: with full admin APIs to the kind of an admin role

40:12 Presenter: to the API and then distinguish between different roles

40:17 Presenter: of users to their application with the client side with the one.

40:20 Presenter: So on the client side, you won’t see the ability to,

40:24 Presenter: for example, go into the admin panel.

40:26 Presenter: But of course, if you just use the APIs,

40:29 Presenter: you can go ahead and use it.

40:30 Presenter: Now, of course, this requires you to understand

40:33 Presenter: the distinction between front-end and back-end,

40:37 Presenter: between APIs and client-side,

40:39 Presenter: and this is an ask that is,

40:42 Presenter: that’s a big ask when you ask it from business users.

40:46 Presenter: And also, as developers, we can also make mistakes, right?

40:49 Presenter: So, and it’s very difficult to make,

40:51 Presenter: to prevent mistakes only with manual intervention.

40:55 Presenter: And so we’ve seen a couple of examples of authorization misuse, but again,

41:02 Presenter: this is something that we see again and again across these different platforms,

41:06 Presenter: especially because low-code, no-code platforms are only as strong as the connections

41:13 Presenter: that they make outside of the platform.

41:17 Presenter: This also brings us to the next part, which is data leakage.

41:20 Presenter: And so of course, as platforms that move data around,

41:24 Presenter: there’s a large risk of data leaking out of organizations.

41:27 Presenter: And so let me show you one example of that

41:29 Presenter: with a concrete application.

41:31 Presenter: This is something that we see,

41:32 Presenter: this is a concrete example,

41:34 Presenter: and you’re seeing this again and again.

41:36 Presenter: Essentially, users are trying to move,

41:43 Presenter: trying to sync their email address

41:46 Presenter: from their corporate account to their personal account.

41:50 Presenter: that users have been trying to do for years, right?

Summary, Takeaways, and Q&A — Part 4

41:52 Presenter: And there are plenty of solutions to try and stop that.

41:56 Presenter: So DLP and things you can put in your email.

42:00 Presenter: And so the way that users are doing it today

42:03 Presenter: with low-code, low-code is that instead of forwarding emails,

42:07 Presenter: they’re simply copying contents.

42:09 Presenter: And so nobody will ever know, right?

42:11 Presenter: Because the copy is being used,

42:14 Presenter: is being done by the low-code, low-code platform

42:16 Presenter: in the low-code, low-code cloud.

42:18 Presenter: it’s being used with two different identities,

42:21 Presenter: one for the corporate account, one for the personal account,

42:23 Presenter: and the email server doesn’t even know that it happened.

42:26 Presenter: So the email server only sees you,

42:29 Presenter: you log into your email, you get an email, that’s it.

42:32 Presenter: They don’t know that you’re, that another,

42:35 Presenter: that somewhere else, the local local platform

42:37 Presenter: is pushing that email to another location.

42:41 Presenter: And so this is something that we’re seeing again and again,

42:43 Presenter: it’s not only happening with emails,

42:45 Presenter: It’s happening with drives and with any sort of file share.

42:50 Presenter: And we’re seeing this with different platforms

42:53 Presenter: and different vendors as well.

42:55 Presenter: Actually, across all of the different organizations

42:58 Presenter: that were part of the statistics that you’re seeing here,

43:00 Presenter: we saw this example at least once.

43:04 Presenter: Here’s another example.

43:06 Presenter: This one is simply showing you the power

43:09 Presenter: that low-code, no-code has to cause harm.

43:12 Presenter: And so in this example,

43:16 Presenter: quick automation, it is triggered manually, it lists out a SharePoint folder, and then it goes

43:22 Presenter: through each SharePoint file and simply encrypts it. And it uses it and it does it with an encryption

43:30 Presenter: step that is helpfully provided by the platforms themselves, because of course there are valid

43:36 Presenter: use cases to encrypt things. And so you can see that malicious intenders can actually use this

43:45 Presenter: And we’ve actually seen this in a few examples,

43:49 Presenter: that this is not the subject of this talk,

43:52 Presenter: but if you’re interested, reach out to me afterwards,

43:55 Presenter: I’ll be happy to share links.

43:59 Presenter: Here’s the next one.

44:00 Presenter: So, when you connect to multiple different locations,

44:04 Presenter: of course, you need to make decisions about the way

44:05 Presenter: that these connections are being made.

44:07 Presenter: And again, keep in mind that the person making that decision

44:11 Presenter: is the developer.

44:12 Presenter: It could be a professional developer.

44:15 Presenter: Now, if you ask a business user the difference

44:18 Presenter: between FTP and FTPS, it really doesn’t make sense.

44:21 Presenter: It doesn’t make sense for them to be the ones

44:23 Presenter: that are asked to answer these questions.

44:26 Presenter: So of course, mistakes are happening.

44:30 Presenter: Let me move forward.

44:31 Presenter: The next thing that we’re seeing

44:34 Presenter: is security misconfiguration.

44:36 Presenter: Now, this is more than just misconfiguration alone.

44:42 Presenter: This is very similar to the types of misconfiguration

44:45 Presenter: and issues we’re seeing in cloud,

44:47 Presenter: because other than the fact that things

44:48 Presenter: are getting misconfigured,

44:50 Presenter: they are getting misconfigured in a way

44:52 Presenter: that can be expected,

44:54 Presenter: in a way that can be enumerated.

44:56 Presenter: And that’s the problem.

44:57 Presenter: Let me give you an example.

44:59 Presenter: This is actually an issue found by a team at UpGuard

45:04 Presenter: at 2021.

45:07 Presenter: Basically, one of the types of applications

45:10 Presenter: that Microsoft local platform can create,

45:13 Presenter: is an application that is exposed to the outside world,

45:15 Presenter: and it creates an API automatically.

45:19 Presenter: That application is supposed to be used as a portal,

45:24 Presenter: as an outbound facing portal.

45:26 Presenter: And so this means that you need to be able to,

45:31 Presenter: so anonymous users should be able to use it as well

45:34 Presenter: before they log in.

45:35 Presenter: The problem here is by default,

45:37 Presenter: all of the information behind the website

45:39 Presenter: was exposed through API to anonymous users.

45:43 Presenter: at Apgarve identified that, they were able to scan

45:46 Presenter: through the internet, of course, all of these websites

45:48 Presenter: are in a single domain, a subdomain of a single domain.

45:52 Presenter: They were able to find those websites

45:53 Presenter: and actually get to business information

45:58 Presenter: that was being kind of kept by those applications.

46:04 Presenter: Now, since then, Microsoft has rapidly changed the default,

46:08 Presenter: but of course, the fact that the default is now secure

46:11 Presenter: doesn’t mean that people cannot misconfigure things.

46:13 Presenter: And so here’s an example, and this is a real example.

46:17 Presenter: Portals are being shared, are being created in this domain.

46:22 Presenter: So it’s a subdomain portal, replace portal with your name.

46:26 Presenter: In the domain, powerappsportals.com.

46:30 Presenter: And if you go to this URL here,

46:32 Presenter: you’ll get to the anonymous endpoint

46:33 Presenter: which exposes the information

46:35 Presenter: if the thing is misconfigured.

46:37 Presenter: Here’s an example.

46:38 Presenter: So this is a real example from an application that we found

46:44 Presenter: kind of looking through different applications

46:46 Presenter: that were out there on the internet.

46:48 Presenter: We were able to find an application that exposed this endpoint.

46:52 Presenter: When you look at this endpoint, you’re seeing the three different entities

46:55 Presenter: that are available for query.

46:56 Presenter: One is a default entity, which really doesn’t have anything.

46:59 Presenter: The second one is entity form set, which is just where form submissions are being stored.

47:05 Presenter: The third one is global variables,

47:07 Presenter: which is kind of interesting, right?

47:09 Presenter: So let’s see what global variables contains.

47:13 Presenter: Of course, it contains authentication,

47:16 Presenter: an OAuth token with access to Azure,

47:19 Presenter: because this is global variables used by the applications.

47:23 Presenter: And so this is a real example.

47:24 Presenter: Of course, we’ve submitted this vulnerability disclosure

47:28 Presenter: to the relevant company, which quickly solves it.

47:31 Presenter: But you can see that this type of problem

47:35 Presenter: to the S3 bucket problem,

47:38 Presenter: open S3 bucket problem we’ve had

47:41 Presenter: with cloud for a long time now.

47:45 Presenter: Moving on, because I see that we don’t have a lot of time,

47:49 Presenter: so forgive me if I kind of skim

47:53 Presenter: through a few of those categories here.

47:56 Presenter: The next part is about injection selfies.

48:00 Presenter: And so of course, these applications expose endpoints,

48:02 Presenter: these end points are prone to injection.

48:06 Presenter: The vendors themselves can try and figure out

48:10 Presenter: and basically sanitize user input.

48:13 Presenter: But of course it really matters what you do

48:14 Presenter: with that user input.

48:15 Presenter: You can’t sanitize input for any type of injection.

48:19 Presenter: It depends whether it goes to a SQL server,

48:22 Presenter: it goes to a JSON parser, it executes its codes.

48:24 Presenter: There are a whole bunch of things that you can see

48:26 Presenter: with information being used by local, no code apps.

48:30 Presenter: And this is actually very similar to the injection surface

48:33 Presenter: that is being exposed by serverless applications,

48:36 Presenter: where you have these triggers that are not only web hooks,

48:42 Presenter: but they can be a file,

48:43 Presenter: they can be an object that is being shared.

Summary, Takeaways, and Q&A — Part 5

48:49 Presenter: One other thing that is crucial with low code, no code,

48:53 Presenter: and we’ve actually seen this in questions as well,

48:55 Presenter: is that this is just another way

48:57 Presenter: where supply chain issues can occur.

49:00 Presenter: Of course, low code, no code only works

49:03 Presenter: because there’s a large number of widgets and components

49:07 Presenter: that are ready for you to pick up and use.

49:09 Presenter: And once you do that, of course, this is an ability

49:13 Presenter: for third party connectors or third party software

49:18 Presenter: to be introduced into your application.

49:20 Presenter: Now, just imagine how would you find

49:23 Presenter: which low-code, no-code applications in your organization

49:27 Presenter: are actually running Log4J.

49:30 Presenter: This is, of course, a real example.

49:33 Presenter: And this is a huge problem.

49:36 Presenter: So we’ve actually been collaborating with the Cyclone DX team

49:39 Presenter: to get low-code integrated into the next release of their SBOM standard

49:48 Presenter: to try and address this issue.

49:53 Presenter: Okay, next up, there’s data and secrets.

49:58 Presenter: Of course, applications,

50:02 Presenter: business critical applications touch business critical data.

50:05 Presenter: They also need to store secrets.

50:07 Presenter: Those secrets can be used for authentication

50:09 Presenter: or to systems across the company.

50:15 Presenter: And so let me give you a concrete example.

50:18 Presenter: And this is from a large IT company.

50:21 Presenter: their HR team created an application that was used to facilitate a giveaway campaign.

50:27 Presenter: So you donate money to charity, you decide which charity you want to donate money to,

50:31 Presenter: and you need to provide your credit card so they’ll be able to charge you.

50:35 Presenter: Now, the thing is, the problem is that the HR team really doesn’t know how to store credit cards, nor should they.

50:42 Presenter: So the credit cards ended up being stored on a default database in plain text

50:48 Presenter: available to the entire organization including guests.

50:52 Presenter: Now this is a kind of a silly example, but it’s a real world example.

50:56 Presenter: And again, it’s not something, we should not be demanding HR teams to figure out how to store credit cards.

51:03 Presenter: We should create guardrails that allow them to work properly and to solve their own needs

51:09 Presenter: and to automatically point them in the right direction.

51:16 Presenter: I’m going to cover the last two categories briefly,

51:21 Presenter: and then I’m going to go to summary and questions.

51:24 Presenter: And so the next category is about asset management.

51:29 Presenter: When you think about so many applications being developed,

51:32 Presenter: so you saw about 75,000 different applications

51:35 Presenter: in the statistics I saw earlier in a single organization.

51:41 Presenter: You can imagine how many of these applications are stale

51:43 Presenter: or applications that no longer have an owner

51:47 Presenter: because the person who’s created them has already moved roles

51:50 Presenter: like three times in the organization and has left the organization.

51:53 Presenter: Finding out where those applications are,

51:57 Presenter: bringing the applications that are business critical under the IT umbrella

52:00 Presenter: is a huge challenge.

52:01 Presenter: And it is required not only to reduce kind of complexity and to reduce technical debt,

52:08 Presenter: but actually to make sure that applications that are business critical, somebody’s looking after them.

52:13 Presenter: And when the creative employee that has created this application leaves the organization,

52:17 Presenter: the organization just doesn’t get stuck.

52:20 Presenter: And the last thing, the last category, is about monitoring and logging.

52:25 Presenter: When you think about the ability of a security team to respond to a threat, to respond to a hack that has something to do with a low-code, no-code application, the ability of that security team to figure out what happened is really small.

52:43 Presenter: It’s really difficult because the logs that these platforms generate are mostly not sufficient or not up to the standards that we’ve seen from other applications.

52:56 Presenter: generalizing here, some platforms are better than others.

53:00 Presenter: But it’s important to note that the level of maturity

53:04 Presenter: of low code with logging, with monitoring,

53:08 Presenter: and also with runtime security,

53:11 Presenter: it’s simply not there.

53:14 Presenter: It’s not as sufficient as it should be.

53:16 Presenter: And so of course, this limits the ability

53:19 Presenter: of security teams to respond to issues.

53:24 Presenter: Now, thank you for bearing with me, and I’m sorry for kind of a bit of,

53:29 Presenter: rationing it a bit at the end.

53:30 Presenter: I wanted to make sure we leave enough time for summary and maybe going through a couple of questions.

53:37 Presenter: And so now that we’ve seen the top 10 and we’ve seen that these issues, so one thing that you can

53:44 Presenter: spot kind of thinking about and retrospectively is the fact that these issues cover both professional

53:50 Presenter: development and business development. Now, yes, the fact that business users are creating

53:56 Presenter: applications can introduce more risk by the fact that they are not security savvy. But of course,

54:02 Presenter: professional developers using low code, they need help too, right? When professional developers

54:09 Presenter: build applications with code, there are so many tools that help them make sure that they

54:14 Presenter: catch mistakes early.

54:16 Presenter: There’s application security and runtime monitoring

54:18 Presenter: and gating and behavioral analytics.

54:23 Presenter: There’s a whole bunch of things that we’re putting out

54:25 Presenter: and processes like security review.

54:28 Presenter: So many processes, so many tools

54:30 Presenter: that are there to help developers spot mistakes early.

54:34 Presenter: With low code, no code, this is really difficult.

54:37 Presenter: And usually you’ll find that the processes

54:41 Presenter: are either lacking or they’re simply not there at all.

54:46 Presenter: And so here’s what we’ve seen today.

54:48 Presenter: We’ve seen that low code, no code is rapidly growing

54:51 Presenter: across the enterprise.

54:53 Presenter: And it’s probably already in your organization

54:55 Presenter: because it comes from many different places,

54:57 Presenter: but including vendors that you’ve already been using

55:01 Presenter: and they have been expanding into a low code, no code platform.

55:05 Presenter: We’ve seen that low code, no code is shifting

55:07 Presenter: from focusing only on professional developers

55:11 Presenter: and business users as well.

55:12 Presenter: And today, low-code, no-code platforms cover both.

55:15 Presenter: They target both professional developers

55:18 Presenter: and business users and anything in between.

55:21 Presenter: We’ve seen that low-code, no-code significantly

55:24 Presenter: is missing SDLC or is missing maturity in SDLC.

55:28 Presenter: And we’ve seen the top 10 risks

55:30 Presenter: that you should address for low-code, no-code.

55:32 Presenter: So if you’re worried about this space,

55:34 Presenter: you’re thinking about this space,

55:36 Presenter: this is where you should focus.

55:37 Presenter: Now, I encourage you,

55:41 Presenter: in this space, reach out to me, you can easily find my credentials,

Summary, Takeaways, and Q&A — Part 6

55:46 Presenter: reach out to the OS group, we are always looking for collaborators.

55:54 Presenter: Here’s one slide about what you can take from this talk. So there’s a huge opportunity here

56:01 Presenter: because we’re finding this, you’re seeing how fast this chart goes or how many applications

56:07 Presenter: are being developed.

56:08 Presenter: In a few years, the number of low-code, no-code applications

56:12 Presenter: with the growth that we’re seeing here,

56:15 Presenter: it’s just going to be so much more than what professional developers can make.

56:19 Presenter: And of course, again, I’ll put a caveat here

56:21 Presenter: that these are different types of applications,

56:24 Presenter: different scale, different complexity.

56:27 Presenter: But the need to secure those applications,

56:29 Presenter: to bring them under the professional, the security umbrella is now.

56:33 Presenter: Because businesses are going to use this.

56:37 Presenter: technology that empowers business users,

56:39 Presenter: we should be pushing for this to be adopted

56:43 Presenter: by our organizations because this could also have,

56:45 Presenter: allow us to gain better visibility than we ever had

56:50 Presenter: to what business users are doing

56:51 Presenter: and to bring them under the security umbrella.

56:54 Presenter: So go to your organization, create those,

56:57 Presenter: expand the application security frameworks

56:59 Presenter: that you have to cover low code, no code.

57:02 Presenter: Look into a low-code SDLC and try to figure out

57:07 Presenter: that local developers achieve the same level

57:11 Presenter: of security guarantees that you have

57:12 Presenter: for application security.

57:14 Presenter: Create approved use cases for low code.

57:16 Presenter: Create guidelines for business users.

57:19 Presenter: Join the OWASP top 10.

57:20 Presenter: And of course, reach out to me and let’s have a chat.

57:25 Presenter: This was very fun.

57:28 Presenter: Thank you everyone for being here.

57:30 Presenter: I’m going to, we have something like two minutes left.

57:33 Presenter: So I think we’re going to try and answer

57:37 Presenter: as we can, but I’ll be happy to answer other questions

57:42 Presenter: after the talk as well.

57:45 Presenter: One thing that, one question that I’m seeing here is that

57:50 Presenter: a lot of the examples were about Office 365

57:53 Presenter: and now we’re seeing different similar issues

57:55 Presenter: across a large variety of local, local platform.

58:00 Presenter: So the answer is unequivocally yes.

58:07 Presenter: problems with Salesforce and with ServiceNow and Workato and Zapier and Appian and OutSystems,

58:13 Presenter: the OS group is much larger than just a nitpicking on Microsoft like I’ve kind of done on this stuff.

58:37 Presenter: I’m seeing here a question about the most important security issue that an organization needs to protect from.

58:43 Presenter: So the OS top 10 tries to be, we try to make it in a way that it’s prioritized, that the risks are prioritized.

58:50 Presenter: But of course, it really depends on your organization.

58:52 Presenter: So it really, the really important thing is for you to figure out as an organization,

58:58 Presenter: where does your security appetite, where does your risk appetite lay and where you should focus.

59:07 Presenter: So that’s kind of a question that needs a lot of context from your side.

59:11 Presenter: We are kind of – we’re out of time, unfortunately, even though I see a lot of other questions.

59:16 Presenter: I will try to reach out by text and answer all of them.

59:19 Presenter: And please, if you have more questions, if you want to learn more, please reach out to me.

59:24 Presenter: I’d be happy to chat.

59:26 Presenter: Thank you very much for your time.

59:27 Presenter: And thank you, RSA, for having me.

59:31 Presenter: Yes, Michael, thank you so much for joining us.

59:34 Presenter: What a fantastic presentation.

59:37 Presenter: joining us today. To find products and solutions related to DevSecOps and application security,

59:42 Presenter: we invite you to visit rsaconference.com forward slash marketplace. Here you’ll find an entire

59:48 Presenter: ecosystem of cybersecurity vendors and service providers who can assist with your specific

59:52 Presenter: needs. Please keep the conversation going on your social channels using the hashtag

59:58 Presenter: RSAC and be sure to connect with Michael on his social channels as well. Thank you.