All talks

BSidesSF 2023 · 2023/04

Sure, Let Business Users Build Their Own. What Could Go Wrong?

Loading presentation…

Read the abstract and transcript

Abstract

Business professionals are increasingly building their own applications with Low-Code/No-Code platforms. And so, enterprises are placing developer-level power in the hands of 100x new business developers. What could go wrong?

Official conference abstract

Transcript

AI generated from recording.

Introduction & Scope; Low‑Code / No‑Code Landscape

00:00 Presenter: Hi, everyone. I’m going to promise you one thing before we start this talk. This is going to be different. Now, you get to decide at the end whether it’s different good or different bad. That’s another thing. But it won’t be the same as other talks you’ll see today because mostly when we talk about security, we focus on the things that developers are building. But this talk is going to be different. It’s going to be focused on what your business users are building and the kind of risks that are exposed by them building their own

00:30 Presenter: applications. So briefly about me and why should you listen to me about this space? I’ve been

00:37 Presenter: working on kind of trying to understand the implications, the security implications of

00:42 Presenter: low-code, no-code applications, those applications that business users are building. For the last

00:47 Presenter: four years or so, I founded a company that’s focused on this space called Xenery. I was part

00:53 Presenter: of the cloud security team at Microsoft, where I got some initial convulsibility into the space.

01:00 Presenter: There is an OWASP group dedicated to top 10 for low-code, no-code.

01:04 Presenter: We’re going to see some of it today.

01:05 Presenter: If you’re interested, please reach out afterwards.

01:09 Presenter: And actually, most of my time is actually spent on the Red Team side,

01:14 Presenter: figuring out how we can use these types of applications to hack the enterprise.

01:18 Presenter: So if you’re interested in that, there’s a bunch more information after it.

01:21 Presenter: You can search for my DEF CON talks.

01:23 Presenter: I gave a couple of them at the last DEF CON.

01:28 Presenter: here’s what we’re going to do today

01:30 Presenter: we’re going to start by making sure we’re all on the same page

01:33 Presenter: on what low-code, no-code actually is

01:35 Presenter: and how fast it’s growing within the enterprise

01:40 Presenter: and I’m hoping to convince you that this is the kind of case

01:44 Presenter: like bring your own device or mobile applications

01:47 Presenter: where we can’t really say this doesn’t belong to us

01:50 Presenter: or this will not happen in our org

01:52 Presenter: we just have to go along with it

01:56 Presenter: the SDLC translates or how it doesn’t translate to low-code, no-code.

02:00 Presenter: And then we’re going to focus on the top risks that we see these applications exposing.

02:06 Presenter: And this is going to be driven by scanning of more than 100,000 of these types of applications

02:14 Presenter: through my company and the OWASP group.

02:17 Presenter: All right.

02:18 Presenter: So we’re going to start by figuring out what low-code, no-code is and why is it…

02:24 Presenter: And it’s promised to make everyone a developer.

02:26 Presenter: And by everyone, I really mean everyone.

02:28 Presenter: I mean people from HR and sales and marketing and across the organization.

02:35 Presenter: This is kind of a joke, but it’s true, right?

02:38 Presenter: Business users or business needs always outweigh our capability as IT to actually answer those needs.

02:45 Presenter: And this has been a problem since forever.

Real‑World Examples of Business Apps; Development Lifecycle & Security Gaps

02:48 Presenter: We’ve been, I mean, the business grows and the rate of growth is larger than what IT can provide.

02:56 Presenter: And this is not only about lack of developers.

02:59 Presenter: It’s not only about kind of a shortage in the number of developers.

03:02 Presenter: It’s just an inherent thing.

03:06 Presenter: Also, kind of when you, as a business user, when you want something addressed, you need to convince people.

03:14 Presenter: You need to get the right attention.

03:16 Presenter: And so you end up waiting.

03:18 Presenter: And so this is what local tries to solve.

03:20 Presenter: And if this sounds like something that is not new, that’s actually that kind of you’ve heard before, it’s not new at all.

03:29 Presenter: It’s actually part of a larger trend that we’ve had for many years now that’s kind of about IT decentralization, about the capability of the business units to operate on their own without central IT.

03:42 Presenter: And there were many different innovations in the past that have actually achieved this.

03:46 Presenter: It’s the number one thing that people think about.

03:49 Presenter: I encourage you to think about kind of when you think about what is the,

03:52 Presenter: how fast can this go is things like Excel or Office.

03:59 Presenter: So Excel has been like the number one tool,

04:02 Presenter: like the single tool that I’ve been using across my career,

04:06 Presenter: no matter how much I’ve learned other things.

04:08 Presenter: Think about the number of jobs that are centered around Excel.

04:12 Presenter: This is the ultimate low-code, no-code tool.

04:14 Presenter: And of course, Excel came with macros, which are kind of our close friends until today.

04:20 Presenter: So low-code is just another iteration on these capabilities that are about empowering business users

04:26 Presenter: or empowering everyone to build applications faster.

04:29 Presenter: And when we think about it this way, it’s easier to understand where is it going.

04:34 Presenter: So it’s going to a place where the business operates independently

04:40 Presenter: and IT can be left outside of the conversation.

04:44 Presenter: Now, one thing that it’s important for us to figure out is to have just a few, it’s important for us for the conversation to have a few concrete examples of applications that were built by business teams or were built with low-code, no-code.

04:57 Presenter: So we all agree or we have something to think about when we consider these applications.

05:04 Presenter: So let me show you a few of them.

05:06 Presenter: Here’s one.

05:06 Presenter: This is actually an example from Microsoft.

05:08 Presenter: If you go and visit or if you went and visit Microsoft offices physically during the pandemic and you had to provide your COVID vaccination proof, this was facilitated through a low-code app.

05:22 Presenter: So you open up this.

05:23 Presenter: This is just a web portal.

05:24 Presenter: You open it up.

05:25 Presenter: You need to upload your COVID certificate.

05:27 Presenter: Of course, this means that this is handling health data, right?

05:32 Presenter: Now, who’s building this app?

05:33 Presenter: It could be professional developers with low-code.

05:35 Presenter: It could be business users.

05:38 Presenter: but the main point is that it’s built with low codings

05:42 Presenter: and it’s a critical app.

05:44 Presenter: And in most cases,

05:46 Presenter: these are not really covered by the security umbrella,

05:48 Presenter: but we’ll touch on that in a moment.

05:51 Presenter: Here’s another example.

05:52 Presenter: This is a famous example by Workato and Slack.

05:57 Presenter: And so Slack is a big Workato customer.

05:59 Presenter: Workato is an integration platform.

06:00 Presenter: And they are using a bunch of Workato automation

06:03 Presenter: to facilitate everything from the order to cache processes.

06:08 Presenter: is of course critical, right?

06:09 Presenter: There cannot be any mistakes here.

06:12 Presenter: And Workato has to be dealt with as a production environment

06:18 Presenter: or a production service in this matter.

06:21 Presenter: Now, let’s see another one, which would be a bit different.

06:25 Presenter: This is another example from Microsoft,

06:27 Presenter: but this time the developer here is clearly a business user.

06:31 Presenter: So here’s the use case here.

06:33 Presenter: There’s the marketing team that is in charge of product launches,

06:38 Presenter: there were several different processes ongoing in parallel

06:41 Presenter: to actually go through those product launches.

06:43 Presenter: So they created an app that facilitated this process,

06:46 Presenter: that allowed everybody to kind of go through the same steps

06:50 Presenter: to launch their product.

06:52 Presenter: This app was developed by the marketing team very quickly

06:55 Presenter: and became the go-to app to work on that process.

06:59 Presenter: So it’s the official app for everybody that wants to launch applications.

07:05 Presenter: And again, this is built by a business user.

07:08 Presenter: this is really cool, but now let’s think about all of the gates,

07:14 Presenter: all of the security controls, everything that we have for professional development

07:18 Presenter: and whether or not this applies here.

07:21 Presenter: Now, one thing you could be thinking right now in order to get yourself off the hook

07:26 Presenter: is that this doesn’t apply to your organization,

07:30 Presenter: that you never have business.

07:31 Presenter: Maybe you’re a bank or financial service or something,

07:34 Presenter: and you’re thinking, well, in my organization,

07:38 Presenter: build things on their own.

07:39 Presenter: And I’m sorry to be the one to say this,

07:42 Presenter: but that’s a very difficult task to achieve.

07:45 Presenter: These things are already there within most enterprises

07:49 Presenter: because low code has been packaged

07:52 Presenter: into existing SaaS products.

07:55 Presenter: And kind of just show me,

07:57 Presenter: there aren’t many enterprises

07:59 Presenter: that don’t have one of these vendors

08:00 Presenter: as kind of deployed in the organization.

Top 10 Risks Overview

08:04 Presenter: And there are, of course, others.

08:05 Presenter: every SaaS platform today is baking in those low-code, no-code capabilities as a way to

08:12 Presenter: extend their platform. But it also means that these are no longer single applications. So

08:18 Presenter: thinking about Office 365 or about Salesforce as a point solution is kind of outdated. Salesforce

08:25 Presenter: is no longer a CRM. It’s an application development platform. And we are not really

08:29 Presenter: treating it that way in most cases.

08:33 Presenter: So if you’re using one of those platforms, these are tools that are already there,

08:38 Presenter: packaged inside, and they are shipped directly to business users.

08:42 Presenter: There’s no asking for permission in that process.

08:46 Presenter: This means that in a typical enterprise that I got to work with,

08:50 Presenter: even though they did not have an official kind of citizen development

08:54 Presenter: or business development initiative,

08:56 Presenter: they had tens of thousands of these applications.

09:00 Presenter: And I’ll show you the statistics in a moment.

09:03 Presenter: When you watch what people that are leading this space

09:08 Presenter: are talking about,

09:09 Presenter: they are talking about it as the next big wave

09:13 Presenter: of application building.

09:15 Presenter: Here are a couple of quotes.

09:17 Presenter: You can see quotes from analysts,

09:20 Presenter: but the more interesting one is actually the quote

09:22 Presenter: for Microsoft, which is sharing kind of their goal in this space.

09:28 Presenter: They’re basically saying, well, we need to build so many apps in the industry.

09:32 Presenter: Developers won’t be able to do it.

09:34 Presenter: So low-code is the way to move forward.

09:36 Presenter: Now, if we think about the fact that these applications are, A, very easy to build, B,

09:42 Presenter: more people can build those applications.

09:44 Presenter: Well, pretty soon, we’re going to be in a situation where most apps, in terms of numbers,

09:49 Presenter: will be built with low-code, low-code, will be built outside of IT.

09:52 Presenter: could be small apps, but they still have identity, they still move data, they still have those

09:58 Presenter: operations that they are doing. And so it’s kind of important for us, failing to put them

10:04 Presenter: under the security umbrella would leave us in a very tough situation. Now, one thing,

10:09 Presenter: I mean, these are quotes that talk about the future, but the more interesting part is whether

10:16 Presenter: they are actually truthful, whether they are, what is the situation today? So I want you

10:22 Presenter: One statistic that I checked kind of a week before

10:25 Presenter: or a few days earlier

10:27 Presenter: is how many .NET developers there are right now.

10:31 Presenter: And according to Microsoft, there are over 5 million.

10:33 Presenter: So I’ll take that as meaning less than six.

10:37 Presenter: Compared to that number, that’s the number today, right?

10:40 Presenter: How many low-code developers,

10:42 Presenter: just using the Microsoft ecosystem, do you think there are?

10:45 Presenter: Just kind of think about it.

10:47 Presenter: Have some sort of an answer.

10:52 Presenter: All right, so I went through Microsoft’s earning reports

10:56 Presenter: for the last few years,

10:58 Presenter: where they mentioned here and there

11:00 Presenter: kind of the number of developers

11:01 Presenter: that are using the low-code, no-code platform.

11:03 Presenter: And of course, this is just Microsoft

11:05 Presenter: because their information is out there,

11:06 Presenter: but the market is much bigger than them.

11:09 Presenter: Here are the statistics.

11:11 Presenter: So they started off with their low-code initiative in 2018.

11:16 Presenter: In 2020, sorry, in 2022,

11:20 Presenter: publicly mentioned that they have more than 7 million developers

11:24 Presenter: that are using their low-code, no-code platform.

11:26 Presenter: And you can see the kind of linear regression that I’ve created here,

11:32 Presenter: which puts them, kind of the prediction is that today there are about 8 million.

11:37 Presenter: But even if you take the 7 million number,

11:40 Presenter: there are more low-code, no-code developers on the Microsoft ecosystem

11:43 Presenter: than .NET developers.

11:44 Presenter: When I saw this, this kind of really surprised me

11:48 Presenter: because we are still thinking of this as a,

11:50 Presenter: we might be thinking of this as a niche thing,

11:52 Presenter: but it’s definitely not, right?

11:54 Presenter: Think about all of the control,

11:57 Presenter: all of the effort that we put in place

11:59 Presenter: to help those .NET developers avoid mistakes

12:02 Presenter: to make sure that the applications

12:03 Presenter: that they are building are secured.

12:05 Presenter: How much effort are we putting

12:06 Presenter: into helping those local and local developers?

12:10 Presenter: Not a comparable amount at all.

12:12 Presenter: All right.

12:14 Presenter: So these are statistics

12:18 Presenter: Microsoft development ecosystem.

12:20 Presenter: But the more important thing for each one of us is

12:23 Presenter: how does it look like for a single organization,

12:26 Presenter: for our organization, for a typical large enterprise,

Detailed Risk Cases — Part 1

12:29 Presenter: how many applications are actually being developed

12:32 Presenter: by these types of platforms?

12:34 Presenter: And so let me show you an example.

12:37 Presenter: And this would be numbers from a real company,

12:41 Presenter: just anonymized.

12:42 Presenter: And they represent, again, a single organization.

12:48 Presenter: Again, from launch in 2018, you can see how the graph goes.

12:54 Presenter: It’s about kind of a quadratic growth there.

12:57 Presenter: You can see that in an amount of something like two years,

13:03 Presenter: they have built about 65,000 applications.

13:08 Presenter: 65,000 applications.

13:10 Presenter: These are numbers that are unprecedented, right?

13:13 Presenter: Nobody is building so many professionally developed applications.

13:18 Presenter: Of course, many of these applications, or even most of these applications are very simple.

13:22 Presenter: They could be like an if this, then that rule, or they could be a single application that

13:27 Presenter: only a user is used, or maybe somebody built an application and never even used it.

13:32 Presenter: It doesn’t really matter.

13:33 Presenter: These applications still have an identity.

13:35 Presenter: They still have the ability to move data and they are built on top of business data by

13:40 Presenter: definition because they are built with these SaaS platforms that already hold your business

13:44 Presenter: data.

13:44 Presenter: Okay, so that’s why it’s important to get on top of this quickly, because the number of applications that are developed is growing really, really, really fast. And again, when you think about when you see this chart, it becomes easier to believe that indeed, most applications, most business applications in the near future would be applications built by the business, rather than applications built by IT, simply because of the of these large numbers.

14:09 Presenter: All right. So here’s a quick recap of what we’ve seen so far. A, we’ve seen that this is a big boost in productivity that is expected to have, or at least the people that are driving it wanted to have at least an Excel level impact.

14:25 Presenter: We’re talking about business critical applications

14:27 Presenter: that are being built here.

14:29 Presenter: Not all of them, but some of them.

14:31 Presenter: And this is, again, available in every major enterprise,

14:34 Presenter: and it doesn’t really matter

14:35 Presenter: whether we choose to enable it or not.

14:38 Presenter: By default, it’s already there.

14:40 Presenter: Right.

14:41 Presenter: So one thing we need to look at,

14:44 Presenter: one thing we need to understand

14:46 Presenter: in order to understand the kind of risks

14:48 Presenter: that these applications expose

14:49 Presenter: is how are they being developed?

14:52 Presenter: So what is the SDLC?

14:55 Presenter: DLC look like for these low-code apps.

14:57 Presenter: And so let me show you an example of one application.

15:00 Presenter: And this will kind of play out in the background,

15:04 Presenter: but this is a very kind of silly example.

15:06 Presenter: What I’m doing here is essentially

15:08 Presenter: I’m trying to fix my own problem.

15:10 Presenter: In my organization, we’re using Slack.

15:12 Presenter: And there’s this feature in Slack

15:14 Presenter: where somebody can mention you on a public channel.

15:16 Presenter: And then there’s this,

15:18 Presenter: you are expected to reply really quickly, right?

15:21 Presenter: Which is kind of annoying.

15:22 Presenter: So what I’m doing here is I’m using an automation in Zapier

15:26 Presenter: where every time somebody mentions me on Slack,

15:29 Presenter: I’ll change my status as if I’m on a call

15:33 Presenter: because that helps.

15:35 Presenter: And then five minutes later,

15:37 Presenter: I’m going to change my status back to available

15:40 Presenter: so nobody would suspect me.

15:43 Presenter: Okay, this is really cool because it’s showing you

15:47 Presenter: actually a really sophisticated application

15:49 Presenter: that I’m building through Zapier here.

15:52 Presenter: through drag and drop. This entire video takes about

15:54 Presenter: two minutes, but just think

15:56 Presenter: about the level of complexity that this

15:58 Presenter: application

16:00 Presenter: needs to handle. It needs to

16:02 Presenter: reach out to, it needs

16:04 Presenter: to authenticate to Slack. It needs

16:06 Presenter: to store some sort of a secret,

16:08 Presenter: right? It needs to subscribe to

16:10 Presenter: Webhook on the Slack side. It needs

16:12 Presenter: to support API changes

16:14 Presenter: by Slack. It needs to have

16:16 Presenter: a state because this delay step, waiting

16:18 Presenter: five minutes, I mean, somebody needs to

16:20 Presenter: wake up after it. This is a significant

16:22 Presenter: of software. And I’m able to build it

16:24 Presenter: simply with drag and drop.

16:26 Presenter: Now, take

16:28 Presenter: this process that you’re seeing right now

16:30 Presenter: and compare it to the SDLC.

16:35 Presenter: I mean, when I’m

16:36 Presenter: finished here and you say it in a moment,

16:38 Presenter: I’ll have a nice little

16:40 Presenter: pop-up that would say, publish

16:42 Presenter: app. That’s it.

16:44 Presenter: Some of the platforms would even automatically

16:46 Presenter: save applications as you build them

16:48 Presenter: and deploy them to production.

16:51 Presenter: This is a

16:52 Presenter: really, this is a really big challenge

16:54 Presenter: because this means that everything

16:59 Presenter: that we’ve baked into the SDLC

17:01 Presenter: doesn’t really apply here.

17:03 Presenter: It gets pushed out of the way.

17:05 Presenter: Now, one thing I will mention,

17:06 Presenter: which is important,

17:07 Presenter: is that in some cases,

17:08 Presenter: professional development teams

17:09 Presenter: are using low-code with an SDLC,

17:12 Presenter: but they are doing this

17:14 Presenter: kind of despite of existing capabilities.

17:18 Presenter: Their life is not easy at all.

17:22 Presenter: So going into the STLC, again, this is just kind of vanilla STLC.

17:27 Presenter: And this is the typical thing that we have for professional development.

17:30 Presenter: Of course, this could vary a lot, but I’m trying to make a point here about low code.

17:36 Presenter: Let’s compare it to what you’ve just seen.

17:40 Presenter: So there’s no real process here.

17:43 Presenter: There’s a single user that thinks about the problem and then solves the problem.

17:48 Presenter: That means that, one, there’s no exchange of hands between different people.

17:54 Presenter: There doesn’t have to be any planning, any monitoring.

17:58 Presenter: Think about what happens if one of these apps get hacked.

18:02 Presenter: Will your SOC even be able to identify it?

18:05 Presenter: If it was identified, will it be able to actually do something with it, investigate it?

18:10 Presenter: I’m not sure.

18:11 Presenter: And more than that, this entire process is up to the business user.

18:18 Presenter: thing to note here is that this is a good thing. This is the feature that is driving this platform.

18:22 Presenter: This is the reason why we have so many apps, because it’s easy to create those apps. So this

18:26 Presenter: is not going to be easily solved. And one other thing that you could be thinking about to get

18:32 Presenter: yourself off the hook is that this is the platform’s fault. Is that the platforms that are

18:37 Presenter: building, that are allowing users to build these things, they should fix the problem. So I’m not

18:42 Presenter: really sure about that because there’s something called the shared responsibility model. We’ve

18:48 Presenter: You can’t expect a cloud provider to solve your problems for you.

18:50 Presenter: When you build an app on top of a platform,

18:54 Presenter: you’re in charge of that app.

18:56 Presenter: The platform is in charge of making secure building blocks,

18:59 Presenter: allowing you to use the platform in a secure way.

19:02 Presenter: But when you build something, you own that thing,

19:04 Presenter: including the security risk of that thing.

19:07 Presenter: Okay.

19:09 Presenter: And what I’m trying to convince you here

19:12 Presenter: is that this must be our problem

19:15 Presenter: because nobody else would fix it for us.

19:18 Presenter: And with that, the next part or the rest of this talk is going to be focused on the types of problems that we’re seeing when these applications actually get developed.

Detailed Risk Cases — Part 2

19:29 Presenter: And what you’re going to see when we go through the top 10 here is concrete examples of how these applications go wrong.

19:40 Presenter: Now, before I show you the actual list, a few words about this project.

19:48 Presenter: years ago. Today, there’s a community of about 200 people that are across the industry that have

19:52 Presenter: joined kind of the different channels there. These are mostly large enterprises that are part of this

20:00 Presenter: group. And if you’re interested, we’re working on the new version of the 2023 version of the top 10.

20:08 Presenter: So if you’re interested, we’re really looking for feedback reviewers, reach out. We’d be happy to

20:13 Presenter: to kind of get you involved.

20:16 Presenter: This community is not only about the top 10.

20:19 Presenter: We’re also doing things that are more on the red teaming side.

20:22 Presenter: You’ll find a bunch of tools that you can pen test your applications with.

20:26 Presenter: So if you’re interested, either go to the link,

20:28 Presenter: so reach out to me afterwards. I’m happy to direct you.

20:31 Presenter: All right.

20:32 Presenter: This entire top 10 list is built on,

20:37 Presenter: is based on the applications that we’re actually seeing in the wild.

20:40 Presenter: So the applications that were built by business teams inside of the organizations that are part of the OVS group.

20:48 Presenter: This is the top 10.

20:50 Presenter: And the top 10 here is, again, different from the kind of regular top 10 for web apps.

20:55 Presenter: And it’s focused on the business logic that these applications represent.

20:59 Presenter: So it’s not about the specific building block.

21:03 Presenter: This is the platform’s fault.

21:04 Presenter: No, this is all focused on your part, on the organization’s part of the shared responsibility model.

21:11 Presenter: All right.

21:13 Presenter: The first problem that we’re seeing again and again in these local platforms is account impersonation.

21:21 Presenter: Let’s put yourself in the shoes of a local platform that’s trying to expand inside of the enterprise.

21:29 Presenter: Again, without asking for permission.

21:30 Presenter: What would be the number one thing

21:32 Presenter: that would make this graph that we saw earlier

21:36 Presenter: kind of not exist,

21:38 Presenter: that would block this graph,

21:39 Presenter: that would block this growth?

21:40 Presenter: The number one thing that would block you

21:42 Presenter: is permissions, right?

21:45 Presenter: If a user has to ask for permission

21:47 Presenter: every time they create an app,

21:49 Presenter: you would never see this growth.

21:50 Presenter: That would never happen.

21:52 Presenter: So how do you circumvent that?

21:53 Presenter: How do you allow somebody from the HR team

21:56 Presenter: to build an app without asking for a service account?

22:00 Presenter: You allow them to use their own identity.

22:04 Presenter: And so the way that these platforms work, the way that these platforms go around this

22:08 Presenter: problem is that they actually copy the user’s refresh tokens and then replay them as part

22:14 Presenter: of the app, which means that actually they are completely breaking the OAuth model or

22:19 Presenter: the permission model that we’re used to inside of the organization.

22:23 Presenter: Many of these integrations are actually built on top of user impersonation.

22:27 Presenter: So we use the logs in, I copy their token and then I replay it.

22:30 Presenter: allow that user to share that token, but we’ll see it in a moment. Now, one other thing that

22:35 Presenter: typically happens is that when somebody builds an application, it could be an important application,

22:40 Presenter: a useful application, they embed their own identity within that application through these

22:45 Presenter: refresh tokens. And now when I share this application with you, you can use it, but

22:50 Presenter: underlying you’re using my own identity. Now, who cares, right? It works. Well, let me show,

22:57 Presenter: let me share a story with you of what could happen.

22:59 Presenter: So this is a real story where a customer care team

23:02 Presenter: in a large organization,

23:04 Presenter: they basically had a problem

23:06 Presenter: where people didn’t have access

23:08 Presenter: to the right information about customers

23:12 Presenter: when they were part of a support ticket.

23:16 Presenter: And so the way that they saw this

23:17 Presenter: is that they created an application

23:18 Presenter: that used somebody from the customer care team

23:23 Presenter: used their own user to go to the customer.

23:27 Presenter: and fetch information about that specific customer.

23:30 Presenter: And they did bake role-based access control into the app itself.

23:33 Presenter: So the app only exposes the customers that you’re related to.

23:40 Presenter: So employees are happy because they can provide more information.

23:45 Presenter: They can do their job better.

Data Leakage & Authorization Issues — Part 1

23:47 Presenter: Customers are happy because they get better service.

23:49 Presenter: Customer care team is happy because they fixed their problem.

23:52 Presenter: Who’s not happy?

23:54 Presenter: The SOC.

23:57 Presenter: from the SOC’s perspective, right?

23:59 Presenter: This is not an app.

24:01 Presenter: This is just, I don’t know,

24:03 Presenter: scraping inside of the organization.

24:05 Presenter: This is a bunch of different requests

24:08 Presenter: across the enterprise,

24:09 Presenter: going through multiple queries,

24:11 Presenter: multiple IPs, different across time,

24:14 Presenter: that are using the same credentials,

24:15 Presenter: which are admin credentials to the database, right?

24:17 Presenter: And this was actually caught

24:19 Presenter: by kind of abnormal activities

24:21 Presenter: that were caught inside the SOC.

24:23 Presenter: And just imagine the SOC analyst

24:27 Presenter: handle this. It took them some time to find that this is actually an application and who’s built

24:33 Presenter: this application. And then the stock analyst reached out to the person on the customer care team.

24:37 Presenter: Imagine that conversation, right? Not an easy conversation. Now, of course, it’s obvious why

24:45 Presenter: this is a problem, right? You are baking in an identity to an application and everybody can use

24:51 Presenter: that identity underlying.

24:53 Presenter: And even though in this specific case,

24:55 Presenter: role-based access control was baked into the app,

24:58 Presenter: in many cases that doesn’t happen.

25:00 Presenter: Some platforms even have a notion

25:02 Presenter: that they call implicit sharing,

25:04 Presenter: which essentially means when I share an application with you,

25:07 Presenter: you get direct access to the underlying data sets.

25:10 Presenter: Even if I revoke access to the app afterwards,

25:14 Presenter: you still get access to those data sets.

25:16 Presenter: So let’s see where that can take us.

25:17 Presenter: And this would be the second thing, the second top 10 here, which is about authorization.

25:23 Presenter: Now, problems with authorization, they’re not new.

25:28 Presenter: There’s nothing new about low-code here.

25:29 Presenter: The only thing that’s new is that this has become much, much, much easier

25:35 Presenter: because low-code platforms are essentially doing credential sharing as a service.

25:39 Presenter: They are providing you with a service that allows you to share your authentication,

25:44 Presenter: to share your identity with other users within your organization.

25:48 Presenter: snapshots of different platforms you’re seeing, Power Automate by Microsoft, Zapier and Wrocato,

25:53 Presenter: this is not picking them to them specifically. Others are doing this as well. They all have a

25:58 Presenter: notion called kind of a default environment or a default folder. And in this default environment,

26:06 Presenter: what you’ll find is credentials, connections that have been shared across your entire organization.

26:11 Presenter: And when I say across your entire organization, I mean everybody in your AAD tenant, that would

26:17 Presenter: example, and this is a single click away when you create those connections. Now, what can a

26:22 Presenter: connection be? You can see, you might be able to see on the slides here a few examples, but in many

26:27 Presenter: organizations, we’re seeing connections to people’s own Outlook and Teams users. We’re seeing FTP

26:34 Presenter: servers, SQL servers. This could also reach out to on-prem through gateways. And so this is just

26:41 Presenter: basically a lateral movement waiting to happen, right? If I get access to any user in the

26:47 Presenter: I can reach out to those platforms and just find those connections that are waiting for me to use.

26:53 Presenter: And we actually have a bunch of tools that could help you identify this within your organization.

26:57 Presenter: I’ll give links to them afterwards.

27:00 Presenter: One other thing that we’re seeing with authorization is basically that people are,

27:07 Presenter: API permissions can be somewhat difficult, especially if you’re not an expert

27:12 Presenter: or if you’re not a professional developer.

27:14 Presenter: And then in many cases, what we’re seeing is that all of the users of an app get provisioned with the same permissions, admin level permissions.

27:22 Presenter: But then they hide the different screen, the administrative screens on the UI side, on the client side.

27:27 Presenter: This is very common, for example, with Salesforce development.

27:30 Presenter: We’ve seen this again and again.

27:31 Presenter: And so here, of course, the problem is obvious, right?

27:34 Presenter: But this is not something that you think about unless you’re aware of the risks.

27:39 Presenter: and we’ve been

27:42 Presenter: kind of in recent years

27:44 Presenter: we’ve gotten a long way

27:46 Presenter: with professional developers becoming

27:48 Presenter: better equipped to

27:49 Presenter: work around security. Business users

27:51 Presenter: are not there. I’m not sure we can expect them

27:53 Presenter: to be there.

27:55 Presenter: Okay, let’s go to the next one.

27:58 Presenter: There are

27:59 Presenter: multiple ways in which we are trying

28:02 Presenter: as enterprises to

28:03 Presenter: block data leakage outside of the org

28:06 Presenter: and one of the things that we’ve been trying

28:09 Presenter: is emails going outside of the organization, right?

28:12 Presenter: So, for example, one very popular thing to do for all of us

28:18 Presenter: is to get the corporate email invites

28:22 Presenter: to our personal Gmail account

28:24 Presenter: because it’s much more comfortable.

28:26 Presenter: Now, organizations are trying to combat, to block this,

28:31 Presenter: and the way that they do it could be through DLP solutions,

28:34 Presenter: could be through something on the email server,

28:37 Presenter: But here’s what’s happening with local platforms.

28:40 Presenter: Instead of forwarding an email,

28:43 Presenter: instead of doing anything that would work over the network,

28:47 Presenter: which would allow a network perimeter appliance to help you,

28:51 Presenter: they are simply connecting with one hand,

28:53 Presenter: with one account to the corporate account,

28:56 Presenter: and with the other hand, with another account

28:58 Presenter: to the personal Gmail account,

28:59 Presenter: and then copying the content.

29:01 Presenter: And this copy operation is being done

29:06 Presenter: form that is owned by the vendor. You don’t have an agent there. There’s no way for you to monitor

29:10 Presenter: it. So again, this is a clear way to export data outside of the organization. There hasn’t been a

29:15 Presenter: single org that I worked with that didn’t have some form of this happen inside of the org.

29:21 Presenter: This could be about email. This could be about moving data between different drives, so SharePoint

29:30 Presenter: and Google Drive, for example. And we also see in many cases that people could build a useful

29:36 Presenter: just use the wrong database

29:39 Presenter: as the database of that application.

29:41 Presenter: Instead of storing it in a corporate database,

29:43 Presenter: they’ll store it in their own personal OneDrive,

29:45 Presenter: for example, or Excel sheet.

29:48 Presenter: One other thing that could happen

29:50 Presenter: is that these applications could be used

29:52 Presenter: to do malicious things.

29:54 Presenter: So for example,

29:55 Presenter: this is an example of a ransomware

29:58 Presenter: for a specific SharePoint site.

29:59 Presenter: So I’m iterating over the entire SharePoint site

30:02 Presenter: and for each file,

30:03 Presenter: I’m simply encrypting that file

30:06 Presenter: function that is provided by the platform and overriding it within the site.

30:11 Presenter: Now, SharePoint has backups, but this same thing could happen on an on-prem machine through

30:18 Presenter: the on-prem connection of those types of platforms.

30:20 Presenter: And this is just one case, but we see in many cases where these platforms by mistake cause

30:26 Presenter: harm.

30:27 Presenter: So there might be conflicting automations that are overriding some files and then things

30:31 Presenter: get changed and you need to walk your way through those types of applications again with

30:35 Presenter: no visibility into it.

30:38 Presenter: one other problem that we’re seeing is authentication and secure communication.

30:42 Presenter: And this is,

30:43 Presenter: this is kind of a silly one,

Data Leakage & Authorization Issues — Part 2

30:45 Presenter: but the power of these platforms is based on the fact that they can connect

30:49 Presenter: across your enterprise.

30:51 Presenter: They come built in with hundreds of different connectors that connect to

30:55 Presenter: SAS and on-prem and others and other places as well.

30:57 Presenter: And when you create those connections,

31:00 Presenter: you as the business user,

31:02 Presenter: you’re in charge of configuring them correctly.

31:04 Presenter: So one thing that we’ve seen,

31:06 Presenter: of weird because this is something we thought we solved already, is the connections to FTP

31:11 Presenter: that are using FTP rather than FTPS.

31:14 Presenter: And again, this is up to the user to the side, the business user.

31:18 Presenter: They can’t really do it on their own.

31:21 Presenter: Okay, let me show you another thing which is pretty common, which is misconfiguration.

31:28 Presenter: This has been a huge thing in cloud for recent years.

31:32 Presenter: And one of the things that you should be thinking about when you think about misconfiguration, as an example, is the open S3 bucket problem with AWS.

31:42 Presenter: So AWS has recently changed the default and made it very difficult for you to open up these buckets.

31:48 Presenter: But we still have open buckets with private corporate information out there because people are making mistakes.

31:55 Presenter: And so it’s not only about the default.

31:56 Presenter: It’s also about helping people not make mistakes.

32:00 Presenter: And so let me show you how this pops up again with low code.

32:04 Presenter: This is an example from Microsoft’s platform.

32:07 Presenter: They have something called Portal Apps,

32:09 Presenter: which is an application that is basically creating a web app for you.

32:13 Presenter: And it allows anonymous users,

32:17 Presenter: so users that are unregistered, not logged in,

32:19 Presenter: to go into the website because, well, it’s a website.

32:23 Presenter: Another feature that it has is an API.

32:26 Presenter: is basically an API endpoint that it sets up for you

32:29 Presenter: that allows you to query all of the different tables

32:32 Presenter: behind this application.

32:35 Presenter: Now, the problem was that the default configuration

32:37 Presenter: was that every user, including anonymous users,

32:41 Presenter: could access every table behind this application

32:45 Presenter: through this API.

32:46 Presenter: And this was actually a problem identified, again,

32:50 Presenter: about a year and a half ago, where the default was like this.

32:53 Presenter: And so it was very easy to find the information that should not be exposed to everyone just through randomly querying those applications.

33:02 Presenter: And so even though the problem has been fixed by Microsoft, the default setting has been changed, this is still happening.

33:09 Presenter: So let me show an example from last year.

33:11 Presenter: And this is a real example.

33:12 Presenter: This is a portal for a company, a financial industry company in the US.

33:17 Presenter: You can see we found this specific portal for that company.

33:22 Presenter: I’ll share with you in a moment how.

33:25 Presenter: And then when you query this API,

33:27 Presenter: you get a list of all of the tables that you can query through the API.

33:30 Presenter: So the default table doesn’t have anything interesting.

33:34 Presenter: Entity form set is just form submissions.

33:36 Presenter: Global variables is kind of interesting, right?

33:39 Presenter: So, of course, it has authentication tokens to Azure and to other services.

33:46 Presenter: of course it’s close to the specific

33:48 Presenter: company where we find this but

33:51 Presenter: the main problem

33:52 Presenter: here and maybe I’ll go back a few

33:54 Presenter: slides so you can figure this out on your own

33:56 Presenter: look at this domain name

33:58 Presenter: all of these applications are

34:00 Presenter: stored in

34:01 Presenter: are served in different subdomains

34:04 Presenter: of this domain so just enumerate this domain

34:07 Presenter: enumerate these different subdomains

34:08 Presenter: go to this endpoint and it’s very

34:10 Presenter: easy to find those configurations

34:13 Presenter: misconfigurations are very much

34:14 Presenter: predictable, which makes this a huge problem.

34:19 Presenter: Okay.

34:20 Presenter: Another thing that we see pop up with the local platforms is injection attacks or more injection

34:28 Presenter: surface.

34:28 Presenter: Now, this could be a tricky one because platforms would tell you that injection has been solved

34:33 Presenter: because you’re using widgets that are provided by the platform.

34:35 Presenter: But if you take input from a user and you plug it into a SQL query that goes out to your SQL server and you don’t sanitize it on the way, then you have created an injection surface.

34:51 Presenter: And again, because this is something that business users are doing or that people that are not part of the security umbrella are doing, then you’re not in a really good position to help them catch it.

35:02 Presenter: Another problem that is surfacing here again is the supply chain.

35:06 Presenter: the only reason why low code is successful

35:08 Presenter: is because there’s a bunch of tools

35:11 Presenter: you can pick up and use from a marketplace

35:14 Presenter: in order to build your application.

Supply Chain, Logging, and Closing — Part 1

35:16 Presenter: There are widgets, there are connectors,

35:18 Presenter: which are kind of wrappers around APIs.

35:21 Presenter: There are different backend operators that you could use.

35:25 Presenter: All of those things,

35:26 Presenter: some of them are built by the platform themselves,

35:29 Presenter: but all of the large platform vendors have a marketplace.

35:33 Presenter: if you think that they are doing

35:36 Presenter: that they are completely owning the risk

35:38 Presenter: of all of the components in their marketplace

35:40 Presenter: you’re absolutely wrong

35:41 Presenter: they might do a single review

35:44 Presenter: but they cannot review every change of each one of those widgets

35:47 Presenter: and also in many cases

35:48 Presenter: the way in which you’re using those different cell party widgets

35:52 Presenter: is that you can just pick them up from GitHub or something

35:55 Presenter: like a zip file

35:56 Presenter: and then you upload it somewhere

35:57 Presenter: there’s no hashing, there’s nothing

36:00 Presenter: so the problem of

36:03 Presenter: supply chain attacks is very difficult to find

36:10 Presenter: and actually identify within those local platforms.

36:12 Presenter: And again, it’s baked in because local platforms

36:15 Presenter: without third-party widgets

36:17 Presenter: would really don’t have a lot of value in them.

36:21 Presenter: Let me show you another kind of example

36:23 Presenter: that we’re seeing a lot.

36:25 Presenter: And this is about sensitive data,

36:27 Presenter: sensitive data and sensitive secrets.

36:33 Presenter: Here’s an example, an app that uses some sort of sensitive data.

36:38 Presenter: A user submits that sensitive data to the app,

36:40 Presenter: and then the app stores the sensitive data on a database in plain text.

36:45 Presenter: This is kind of funny, and again, not new,

36:48 Presenter: but because business users are building these applications,

36:50 Presenter: how would they know how to store credit cards?

36:52 Presenter: It’s not really their role.

36:54 Presenter: So let me show you, let me share a specific example.

36:57 Presenter: This is an HR team at a large IT company.

37:00 Presenter: Basically, they wanted to do a giveaway campaign

37:03 Presenter: where people can donate money to charity.

37:06 Presenter: So they created a small application that did a very simple thing.

37:10 Presenter: You register to the application, you provide your credit card,

37:13 Presenter: and you choose the charity you’d like to donate to,

37:16 Presenter: and the company will donate as well.

37:18 Presenter: Now, the credit cards that were collected there were stored,

37:22 Presenter: A, in plain text, B, in an environment which was kind of a development environment

37:27 Presenter: shared across the entire organization.

37:30 Presenter: So again, this is very cool that business users are able to do this, but this is kind of a problem.

37:35 Presenter: And by the way, they found this when compliance auditors started asking questions, which is kind of a difficult place to be at.

37:43 Presenter: And we are seeing this thing about kind of sensitive data that’s being handled by these applications a lot.

37:50 Presenter: And again, because these platforms are built, these local platforms are built on top of SaaS platforms that contain business data,

37:58 Presenter: it’s very difficult to create those distinctions to make sure that these applications are not touching business data, for example.

38:07 Presenter: One other thing that is clear is that most of these applications are built outside of IT’s eye or control.

38:15 Presenter: There are so many cases where somebody builds a successful application, other people are using them, and then this person leaves the organization.

38:23 Presenter: Okay, what happens now?

38:24 Presenter: This application remains, I mean, it’s used until it doesn’t work anymore.

38:30 Presenter: And then who would you call?

38:32 Presenter: What would happen if this application gets hacked?

38:34 Presenter: Who would own it?

38:35 Presenter: I mean, this is a really difficult situation.

38:39 Presenter: And this is because we, as the people that are in charge of kind of securing the organization,

38:44 Presenter: we’re really not aware of them.

38:45 Presenter: One of the key things that I see people try to do here is focus on applications that become viral within the organization.

38:53 Presenter: So focus on those apps that are not used by one user or a couple of users, but used by a lot of different users within the org.

39:01 Presenter: And the last problem that I’ll mention here is logging and monitoring.

39:06 Presenter: So it’s funny, but there are kind of two separate problems here, which are kind of the opposite.

39:12 Presenter: One is that in many cases, there are no logs at all.

39:15 Presenter: So you won’t find, or the logs are not available to the right people.

39:20 Presenter: So again, just think about whether you can,

39:22 Presenter: if something happens with one of these applications,

39:25 Presenter: whether you can actually create an investigation to find out what happened,

39:28 Presenter: who is logging into these applications,

39:30 Presenter: what data did they provide to those users?

39:33 Presenter: So those things don’t really exist.

39:35 Presenter: But on the other hand, some of these actual components,

39:39 Presenter: for example, these automations, have a habit of recording everything.

39:45 Presenter: I mean all of the data that goes through those automations.

39:49 Presenter: And so one of the issues that we’re seeing is that,

39:52 Presenter: let’s say I build an application

39:55 Presenter: that allows you to check your email or something.

39:58 Presenter: Okay, now you can use the application,

40:02 Presenter: but as the builder of that application,

40:04 Presenter: I can access the logs that are available to that application,

40:08 Presenter: which can include the actual data that goes through the app.

40:12 Presenter: Okay, which is again a very clear path

40:15 Presenter: to privilege the escalation of one user

40:19 Presenter: to be able to view things by other users.

40:21 Presenter: And actually, previously,

40:25 Presenter: earlier this year at DefCon,

40:26 Presenter: I showed how this specific capability

40:28 Presenter: could be used to move laterally across the organization.

40:32 Presenter: All right.

40:33 Presenter: So we have seen,

40:36 Presenter: let’s talk about what we’ve seen so far.

40:39 Presenter: We’ve seen that low-code, no-code

40:41 Presenter: is rapidly growing within the organization.

40:43 Presenter: and chances are it’s already there in your org.

40:47 Presenter: And I’m not saying this as,

40:49 Presenter: you shouldn’t be worried about this.

40:51 Presenter: You should bring it under the security umbrella.

40:54 Presenter: I mean, security, business users are,

40:56 Presenter: in many cases, you’ll find that there are teams

40:59 Presenter: that have already started developing

41:00 Presenter: critical applications on these platforms

41:02 Presenter: and they are scared because nobody’s helping them

41:05 Presenter: to make sure they’re doing the right thing.

41:07 Presenter: There’s a huge opportunity here for us

41:10 Presenter: to be part of that conversation.

41:13 Presenter: we saw that there’s missing SDLC.

41:15 Presenter: In some cases, there is some SDLC,

41:17 Presenter: but in many cases, you’ll find none.

41:19 Presenter: And I really encourage you to look at the OWASP top 10.

41:23 Presenter: There are a bunch of more examples

41:24 Presenter: that I haven’t shared here already.

41:26 Presenter: And actually, the new version that we’re going to share

41:30 Presenter: is going to be much deeper.

41:31 Presenter: One of the things that we are working on

41:33 Presenter: is having those top 10 written in a way

41:36 Presenter: that you can actually give your business users

41:38 Presenter: and they will understand

41:39 Presenter: to help them be closer to the security mindset.

41:44 Presenter: The opportunities for you to take,

41:46 Presenter: and this might be the most important thing to take out of the slides,

41:50 Presenter: out of this talk,

41:52 Presenter: there’s a huge opportunity for you to be the champion of this space

41:55 Presenter: within your organization.

41:57 Presenter: AppSec needs to be part of the low-code, no-code conversation

42:00 Presenter: or the business development conversation.

42:02 Presenter: We are seeing organizations that are creating security frameworks

42:05 Presenter: or basically extending the secure development policies

42:09 Presenter: they have two business users.

42:11 Presenter: And of course, there’s a lot of need to think about

42:14 Presenter: what exactly do you want to build there?

Supply Chain, Logging, and Closing — Part 2

42:16 Presenter: What use cases are approved?

42:18 Presenter: How are you checking those use cases?

42:21 Presenter: How are you providing galleries

42:23 Presenter: for those users to build correctly?

42:26 Presenter: But instead of just thinking,

42:29 Presenter: so they don’t need to think about security.

42:31 Presenter: They can just continue building,

42:32 Presenter: but you protect them along the way.

42:35 Presenter: If you’re interested, please reach out.

42:38 Presenter: and I think we have some time for questions

42:40 Presenter: so thank you very much

42:49 Presenter: I might do this so we have light

42:54 Presenter: thank you, I’ll be coming around

42:55 Presenter: and let’s see, okay now I can see

43:00 Presenter: you raised your hand?

43:01 Presenter: okay, come on

43:04 Presenter: wait, wait, I’m going to give you the microphone

43:10 Presenter: So something that came to mind for me was when we’ve seen people whose, say, Office 365 email has been compromised and the bad guys tend to create outlook rules and things like that to forward emails for business email compromise and things like that.

43:27 Presenter: I was wondering if you’ve seen any instances where these automations were used to do that as well, like the email things that you suggested.

43:34 Presenter: So, unfortunately, yes. About three years ago, Microsoft published a report where a single organization was attacked by something like four different malware groups.

43:45 Presenter: And defenders were looking to clear the network out of malware for like six months.

43:50 Presenter: And they weren’t able to find what was going on.

43:55 Presenter: After six months, they found a single power automation.

43:59 Presenter: They did a very simple thing. It was running under administrative permissions.

44:04 Presenter: It used the e-discovery tools by Microsoft to find sensitive information, secrets, whatever it could, across the organization, store all of them, and send them to an HTTP endpoint.

44:16 Presenter: And this was a single automation that, I mean, just trying to find this automation took so much time.

44:22 Presenter: And so this is, I can share a link afterwards if you’re interested.

44:26 Presenter: Shoot me an email or on Twitter.

44:29 Presenter: But this was actually a long time ago.

44:34 Presenter: We’ve seen this happen mostly as mistakes, people that are making mistakes and just moving that outside of the org.

44:45 Presenter: Thank you.

44:46 Presenter: On to the next question.

44:52 Presenter: Any ideas on a strategy for how to detect and find these things in your organization?

44:58 Presenter: Yes.

44:59 Presenter: So I do have one optimistic message here.

45:03 Presenter: we have to remember that these things

45:07 Presenter: I mean data that was

45:09 Presenter: these low code applications are replacing

45:11 Presenter: what you can call copy and paste integration

45:14 Presenter: people have been moving files from one place to another

45:17 Presenter: since forever and we’ve been trying to address it with DLP solutions

45:20 Presenter: and other things for a long time and we haven’t been successful at all

45:23 Presenter: but now when business users are using these low code

45:26 Presenter: no code platforms there’s somebody you can ask

45:29 Presenter: tell me you can go to the platform

45:32 Presenter: and ask what are all of the applications that are available in your platform

45:36 Presenter: that have been built on top of your platform.

45:38 Presenter: Now, of course, it does require you to understand what these applications are doing,

45:43 Presenter: to scan, for example, the definitions of those applications

45:47 Presenter: to actually figure out what data they’re attaching.

45:49 Presenter: And we are seeing organizations that are actually going through those processes.

45:54 Presenter: So you can do it.

45:55 Presenter: You can automatically scan those applications, find inventory them,

45:59 Presenter: find vulnerabilities, collect logs.

46:02 Presenter: of work that you need to do in order to do that, you do have an API for some of it.

46:08 Presenter: So you do have, for example, an API to query what all of the applications that exist that

46:13 Presenter: is much more than we had when businesses were just copying files.

46:19 Presenter: Thank you.

46:21 Presenter: We have four minutes more left for questions.

46:24 Presenter: Anybody else?

46:28 Presenter: Thank you.

46:29 Presenter: it seemed like one of the largest issues you mentioned with this was role-based authentication

46:34 Presenter: um it seems like largely that’s because it’s operating outside of the existing structures we

46:42 Presenter: have for auditing that you mentioned sock i believe do you think that we would still see benefit

46:49 Presenter: in the low code no code solutions if we force them to go through the more standard process

46:55 Presenter: of role-based authentication?

46:58 Presenter: And how do you see that working

46:59 Presenter: when currently they seem to be working

47:02 Presenter: around current authorization structures?

47:06 Presenter: Do you think, and I know you said

47:08 Presenter: that we can’t rely on them to,

47:10 Presenter: or rely on the tools to fix the problems for us.

47:15 Presenter: Do you think it’s reasonable

47:16 Presenter: that they should be working

47:17 Presenter: within current structures such as OAuth?

47:20 Presenter: So I think all of the platforms

47:25 Presenter: you to build your applications and connect to things with service accounts rather than users,

47:31 Presenter: which would be the best case scenario, right? Because then you can provision those accounts,

47:36 Presenter: you can monitor them, et cetera. The problem is that this means that somebody needs to ask for

47:42 Presenter: permissions, which creates a roadblock, which means that the applications won’t get fully adopted,

47:47 Presenter: adopted, which means in my, at least in my view, that it would never really happen.

47:54 Presenter: I mean, again, these capabilities are available.

47:57 Presenter: In some platforms, people are actually using service accounts, but enforcing the use of

48:02 Presenter: service accounts, I don’t see a way for this to work together with the exponential growth

48:09 Presenter: or with the quadratic growth that we’ve seen earlier.

48:13 Presenter: There are cases, and connecting this to the previous question, one of the things that I do see enterprises do is that they make sure that for some use cases, so for example, if you’re touching business-sensitive data, if you’re touching credit cards, you have to use a service account.

48:30 Presenter: But then you need some way to actually enforce that rule.

48:39 Presenter: Thank you, and this will be our last question.

48:42 Presenter: We have one minute left.

48:45 Presenter: Yeah, somebody who is kind of dealing with a new low-code environment coming in, I echo everything you said.

48:55 Presenter: One of the things in the security organization, we sort of caught it sort of late into the adoption cycle.

49:01 Presenter: and one of the things that we’ve had to do is basically say that only modules that have been vetted

49:10 Presenter: are allowed to be brought into our organization so something equivalent to artifactory kind of a

Supply Chain, Logging, and Closing — Part 3

49:16 Presenter: model and we’ve also had to work with the vendor applying heavy pressure to allow our sonar cube

49:26 Presenter: rules, for example, be applied.

49:29 Presenter: And

49:31 Presenter: just as a normal

49:32 Presenter: sort of thing with hard

49:34 Presenter: guard rail mechanisms, it was

49:36 Presenter: something that the no-code, low-code

49:38 Presenter: vendor was like very, very, very

49:40 Presenter: grumpy about. But it’s

49:42 Presenter: something that we’ve really twisted the screws

49:44 Presenter: on. So we are,

49:46 Presenter: you know, I’m not going to say what my organization is

49:48 Presenter: obviously, but it’s something that

49:50 Presenter: everything you said is absolutely 100%.

49:52 Presenter: And we’ve been applying screws on that stuff.

49:56 Presenter: I think that one of the mistakes I think we should avoid,

50:02 Presenter: I mean, we must push the vendors to be better.

50:06 Presenter: However, we need to understand that there’s an entire ecosystem

50:11 Presenter: that needs to be built here, right?

50:13 Presenter: When you build a normal app, a ProCode app,

50:17 Presenter: you have shift left, you have runtime monitoring,

50:21 Presenter: you have network perimeter,

50:23 Presenter: you have a bunch of things that are helping you prevent mistakes

50:26 Presenter: prevent attacks. In no code, you don’t

50:28 Presenter: really have all of them, and

50:30 Presenter: vendors would solve everything for us, but

50:32 Presenter: vendors need to make it easier for us

50:34 Presenter: to actually solve those problems.

50:36 Presenter: I know we’re out of time. Thank you very much.

50:38 Presenter: I’ll stay here for questions,

50:40 Presenter: and if you can’t catch me here,

50:42 Presenter: reach out on Twitter. Thanks.

50:44 Presenter: applause