SANS Cybersecurity Leadership Summit UK 2023 · 2023/04
Credential Sharing as a Service: the Dark Side of No Code
Abstract
Business professionals are no longer waiting for IT to address their needs. Instead, they are increasingly building their own applications with Low-Code/No-Code platforms. Recent surveys show that most enterprise apps are now built outside of IT by business professionals who hold no previous experience in building software. In this presentation, we will share extensive research on the security of Low-Code applications based on scanning >100K applications across hundreds of enterprise environments. We will show how this research led to the creation of the OWASP Top 10 Security Risks for Low-Code/No-Code and showcase those risks. Next, we will demonstrate how most applications get identity, access and data flow wrong, cover a wide range of security issues found in real environments, and share their backstories and implications.