Abstract
Business professionals are increasingly building their own applications with Low-Code/No-Code platforms. And so, enterprises are placing developer-level power in the hands of 100x new business developers. What could go wrong?
Transcript
AI generated from recording.
Introduction & Scope; Low‑Code / No‑Code Landscape
00:00 Presenter: Hi, everyone. I’m going to promise you one thing before we start this talk. This is going to be different. Now, you get to decide at the end whether it’s different good or different bad. That’s another thing. But it won’t be the same as other talks you’ll see today because mostly when we talk about security, we focus on the things that developers are building. But this talk is going to be different. It’s going to be focused on what your business users are building and the kind of risks that are exposed by them building their own
00:30 Presenter: applications. So briefly about me and why should you listen to me about this space? I’ve been
00:37 Presenter: working on kind of trying to understand the implications, the security implications of
00:42 Presenter: low-code, no-code applications, those applications that business users are building. For the last
00:47 Presenter: four years or so, I founded a company that’s focused on this space called Xenery. I was part
00:53 Presenter: of the cloud security team at Microsoft, where I got some initial convulsibility into the space.
01:00 Presenter: There is an OWASP group dedicated to top 10 for low-code, no-code.
01:04 Presenter: We’re going to see some of it today.
01:05 Presenter: If you’re interested, please reach out afterwards.
01:09 Presenter: And actually, most of my time is actually spent on the Red Team side,
01:14 Presenter: figuring out how we can use these types of applications to hack the enterprise.
01:18 Presenter: So if you’re interested in that, there’s a bunch more information after it.
01:21 Presenter: You can search for my DEF CON talks.
01:23 Presenter: I gave a couple of them at the last DEF CON.
01:28 Presenter: here’s what we’re going to do today
01:30 Presenter: we’re going to start by making sure we’re all on the same page
01:33 Presenter: on what low-code, no-code actually is
01:35 Presenter: and how fast it’s growing within the enterprise
01:40 Presenter: and I’m hoping to convince you that this is the kind of case
01:44 Presenter: like bring your own device or mobile applications
01:47 Presenter: where we can’t really say this doesn’t belong to us
01:50 Presenter: or this will not happen in our org
01:52 Presenter: we just have to go along with it
01:56 Presenter: the SDLC translates or how it doesn’t translate to low-code, no-code.
02:00 Presenter: And then we’re going to focus on the top risks that we see these applications exposing.
02:06 Presenter: And this is going to be driven by scanning of more than 100,000 of these types of applications
02:14 Presenter: through my company and the OWASP group.
02:17 Presenter: All right.
02:18 Presenter: So we’re going to start by figuring out what low-code, no-code is and why is it…
02:24 Presenter: And it’s promised to make everyone a developer.
02:26 Presenter: And by everyone, I really mean everyone.
02:28 Presenter: I mean people from HR and sales and marketing and across the organization.
02:35 Presenter: This is kind of a joke, but it’s true, right?
02:38 Presenter: Business users or business needs always outweigh our capability as IT to actually answer those needs.
02:45 Presenter: And this has been a problem since forever.
Real‑World Examples of Business Apps; Development Lifecycle & Security Gaps
02:48 Presenter: We’ve been, I mean, the business grows and the rate of growth is larger than what IT can provide.
02:56 Presenter: And this is not only about lack of developers.
02:59 Presenter: It’s not only about kind of a shortage in the number of developers.
03:02 Presenter: It’s just an inherent thing.
03:06 Presenter: Also, kind of when you, as a business user, when you want something addressed, you need to convince people.
03:14 Presenter: You need to get the right attention.
03:16 Presenter: And so you end up waiting.
03:18 Presenter: And so this is what local tries to solve.
03:20 Presenter: And if this sounds like something that is not new, that’s actually that kind of you’ve heard before, it’s not new at all.
03:29 Presenter: It’s actually part of a larger trend that we’ve had for many years now that’s kind of about IT decentralization, about the capability of the business units to operate on their own without central IT.
03:42 Presenter: And there were many different innovations in the past that have actually achieved this.
03:46 Presenter: It’s the number one thing that people think about.
03:49 Presenter: I encourage you to think about kind of when you think about what is the,
03:52 Presenter: how fast can this go is things like Excel or Office.
03:59 Presenter: So Excel has been like the number one tool,
04:02 Presenter: like the single tool that I’ve been using across my career,
04:06 Presenter: no matter how much I’ve learned other things.
04:08 Presenter: Think about the number of jobs that are centered around Excel.
04:12 Presenter: This is the ultimate low-code, no-code tool.
04:14 Presenter: And of course, Excel came with macros, which are kind of our close friends until today.
04:20 Presenter: So low-code is just another iteration on these capabilities that are about empowering business users
04:26 Presenter: or empowering everyone to build applications faster.
04:29 Presenter: And when we think about it this way, it’s easier to understand where is it going.
04:34 Presenter: So it’s going to a place where the business operates independently
04:40 Presenter: and IT can be left outside of the conversation.
04:44 Presenter: Now, one thing that it’s important for us to figure out is to have just a few, it’s important for us for the conversation to have a few concrete examples of applications that were built by business teams or were built with low-code, no-code.
04:57 Presenter: So we all agree or we have something to think about when we consider these applications.
05:04 Presenter: So let me show you a few of them.
05:06 Presenter: Here’s one.
05:06 Presenter: This is actually an example from Microsoft.
05:08 Presenter: If you go and visit or if you went and visit Microsoft offices physically during the pandemic and you had to provide your COVID vaccination proof, this was facilitated through a low-code app.
05:22 Presenter: So you open up this.
05:23 Presenter: This is just a web portal.
05:24 Presenter: You open it up.
05:25 Presenter: You need to upload your COVID certificate.
05:27 Presenter: Of course, this means that this is handling health data, right?
05:32 Presenter: Now, who’s building this app?
05:33 Presenter: It could be professional developers with low-code.
05:35 Presenter: It could be business users.
05:38 Presenter: but the main point is that it’s built with low codings
05:42 Presenter: and it’s a critical app.
05:44 Presenter: And in most cases,
05:46 Presenter: these are not really covered by the security umbrella,
05:48 Presenter: but we’ll touch on that in a moment.
05:51 Presenter: Here’s another example.
05:52 Presenter: This is a famous example by Workato and Slack.
05:57 Presenter: And so Slack is a big Workato customer.
05:59 Presenter: Workato is an integration platform.
06:00 Presenter: And they are using a bunch of Workato automation
06:03 Presenter: to facilitate everything from the order to cache processes.
06:08 Presenter: is of course critical, right?
06:09 Presenter: There cannot be any mistakes here.
06:12 Presenter: And Workato has to be dealt with as a production environment
06:18 Presenter: or a production service in this matter.
06:21 Presenter: Now, let’s see another one, which would be a bit different.
06:25 Presenter: This is another example from Microsoft,
06:27 Presenter: but this time the developer here is clearly a business user.
06:31 Presenter: So here’s the use case here.
06:33 Presenter: There’s the marketing team that is in charge of product launches,
06:38 Presenter: there were several different processes ongoing in parallel
06:41 Presenter: to actually go through those product launches.
06:43 Presenter: So they created an app that facilitated this process,
06:46 Presenter: that allowed everybody to kind of go through the same steps
06:50 Presenter: to launch their product.
06:52 Presenter: This app was developed by the marketing team very quickly
06:55 Presenter: and became the go-to app to work on that process.
06:59 Presenter: So it’s the official app for everybody that wants to launch applications.
07:05 Presenter: And again, this is built by a business user.
07:08 Presenter: this is really cool, but now let’s think about all of the gates,
07:14 Presenter: all of the security controls, everything that we have for professional development
07:18 Presenter: and whether or not this applies here.
07:21 Presenter: Now, one thing you could be thinking right now in order to get yourself off the hook
07:26 Presenter: is that this doesn’t apply to your organization,
07:30 Presenter: that you never have business.
07:31 Presenter: Maybe you’re a bank or financial service or something,
07:34 Presenter: and you’re thinking, well, in my organization,
07:38 Presenter: build things on their own.
07:39 Presenter: And I’m sorry to be the one to say this,
07:42 Presenter: but that’s a very difficult task to achieve.
07:45 Presenter: These things are already there within most enterprises
07:49 Presenter: because low code has been packaged
07:52 Presenter: into existing SaaS products.
07:55 Presenter: And kind of just show me,
07:57 Presenter: there aren’t many enterprises
07:59 Presenter: that don’t have one of these vendors
08:00 Presenter: as kind of deployed in the organization.
Top 10 Risks Overview
08:04 Presenter: And there are, of course, others.
08:05 Presenter: every SaaS platform today is baking in those low-code, no-code capabilities as a way to
08:12 Presenter: extend their platform. But it also means that these are no longer single applications. So
08:18 Presenter: thinking about Office 365 or about Salesforce as a point solution is kind of outdated. Salesforce
08:25 Presenter: is no longer a CRM. It’s an application development platform. And we are not really
08:29 Presenter: treating it that way in most cases.
08:33 Presenter: So if you’re using one of those platforms, these are tools that are already there,
08:38 Presenter: packaged inside, and they are shipped directly to business users.
08:42 Presenter: There’s no asking for permission in that process.
08:46 Presenter: This means that in a typical enterprise that I got to work with,
08:50 Presenter: even though they did not have an official kind of citizen development
08:54 Presenter: or business development initiative,
08:56 Presenter: they had tens of thousands of these applications.
09:00 Presenter: And I’ll show you the statistics in a moment.
09:03 Presenter: When you watch what people that are leading this space
09:08 Presenter: are talking about,
09:09 Presenter: they are talking about it as the next big wave
09:13 Presenter: of application building.
09:15 Presenter: Here are a couple of quotes.
09:17 Presenter: You can see quotes from analysts,
09:20 Presenter: but the more interesting one is actually the quote
09:22 Presenter: for Microsoft, which is sharing kind of their goal in this space.
09:28 Presenter: They’re basically saying, well, we need to build so many apps in the industry.
09:32 Presenter: Developers won’t be able to do it.
09:34 Presenter: So low-code is the way to move forward.
09:36 Presenter: Now, if we think about the fact that these applications are, A, very easy to build, B,
09:42 Presenter: more people can build those applications.
09:44 Presenter: Well, pretty soon, we’re going to be in a situation where most apps, in terms of numbers,
09:49 Presenter: will be built with low-code, low-code, will be built outside of IT.
09:52 Presenter: could be small apps, but they still have identity, they still move data, they still have those
09:58 Presenter: operations that they are doing. And so it’s kind of important for us, failing to put them
10:04 Presenter: under the security umbrella would leave us in a very tough situation. Now, one thing,
10:09 Presenter: I mean, these are quotes that talk about the future, but the more interesting part is whether
10:16 Presenter: they are actually truthful, whether they are, what is the situation today? So I want you
10:22 Presenter: One statistic that I checked kind of a week before
10:25 Presenter: or a few days earlier
10:27 Presenter: is how many .NET developers there are right now.
10:31 Presenter: And according to Microsoft, there are over 5 million.
10:33 Presenter: So I’ll take that as meaning less than six.
10:37 Presenter: Compared to that number, that’s the number today, right?
10:40 Presenter: How many low-code developers,
10:42 Presenter: just using the Microsoft ecosystem, do you think there are?
10:45 Presenter: Just kind of think about it.
10:47 Presenter: Have some sort of an answer.
10:52 Presenter: All right, so I went through Microsoft’s earning reports
10:56 Presenter: for the last few years,
10:58 Presenter: where they mentioned here and there
11:00 Presenter: kind of the number of developers
11:01 Presenter: that are using the low-code, no-code platform.
11:03 Presenter: And of course, this is just Microsoft
11:05 Presenter: because their information is out there,
11:06 Presenter: but the market is much bigger than them.
11:09 Presenter: Here are the statistics.
11:11 Presenter: So they started off with their low-code initiative in 2018.
11:16 Presenter: In 2020, sorry, in 2022,
11:20 Presenter: publicly mentioned that they have more than 7 million developers
11:24 Presenter: that are using their low-code, no-code platform.
11:26 Presenter: And you can see the kind of linear regression that I’ve created here,
11:32 Presenter: which puts them, kind of the prediction is that today there are about 8 million.
11:37 Presenter: But even if you take the 7 million number,
11:40 Presenter: there are more low-code, no-code developers on the Microsoft ecosystem
11:43 Presenter: than .NET developers.
11:44 Presenter: When I saw this, this kind of really surprised me
11:48 Presenter: because we are still thinking of this as a,
11:50 Presenter: we might be thinking of this as a niche thing,
11:52 Presenter: but it’s definitely not, right?
11:54 Presenter: Think about all of the control,
11:57 Presenter: all of the effort that we put in place
11:59 Presenter: to help those .NET developers avoid mistakes
12:02 Presenter: to make sure that the applications
12:03 Presenter: that they are building are secured.
12:05 Presenter: How much effort are we putting
12:06 Presenter: into helping those local and local developers?
12:10 Presenter: Not a comparable amount at all.
12:12 Presenter: All right.
12:14 Presenter: So these are statistics
12:18 Presenter: Microsoft development ecosystem.
12:20 Presenter: But the more important thing for each one of us is
12:23 Presenter: how does it look like for a single organization,
12:26 Presenter: for our organization, for a typical large enterprise,
Detailed Risk Cases — Part 1
12:29 Presenter: how many applications are actually being developed
12:32 Presenter: by these types of platforms?
12:34 Presenter: And so let me show you an example.
12:37 Presenter: And this would be numbers from a real company,
12:41 Presenter: just anonymized.
12:42 Presenter: And they represent, again, a single organization.
12:48 Presenter: Again, from launch in 2018, you can see how the graph goes.
12:54 Presenter: It’s about kind of a quadratic growth there.
12:57 Presenter: You can see that in an amount of something like two years,
13:03 Presenter: they have built about 65,000 applications.
13:08 Presenter: 65,000 applications.
13:10 Presenter: These are numbers that are unprecedented, right?
13:13 Presenter: Nobody is building so many professionally developed applications.
13:18 Presenter: Of course, many of these applications, or even most of these applications are very simple.
13:22 Presenter: They could be like an if this, then that rule, or they could be a single application that
13:27 Presenter: only a user is used, or maybe somebody built an application and never even used it.
13:32 Presenter: It doesn’t really matter.
13:33 Presenter: These applications still have an identity.
13:35 Presenter: They still have the ability to move data and they are built on top of business data by
13:40 Presenter: definition because they are built with these SaaS platforms that already hold your business
13:44 Presenter: data.
13:44 Presenter: Okay, so that’s why it’s important to get on top of this quickly, because the number of applications that are developed is growing really, really, really fast. And again, when you think about when you see this chart, it becomes easier to believe that indeed, most applications, most business applications in the near future would be applications built by the business, rather than applications built by IT, simply because of the of these large numbers.
14:09 Presenter: All right. So here’s a quick recap of what we’ve seen so far. A, we’ve seen that this is a big boost in productivity that is expected to have, or at least the people that are driving it wanted to have at least an Excel level impact.
14:25 Presenter: We’re talking about business critical applications
14:27 Presenter: that are being built here.
14:29 Presenter: Not all of them, but some of them.
14:31 Presenter: And this is, again, available in every major enterprise,
14:34 Presenter: and it doesn’t really matter
14:35 Presenter: whether we choose to enable it or not.
14:38 Presenter: By default, it’s already there.
14:40 Presenter: Right.
14:41 Presenter: So one thing we need to look at,
14:44 Presenter: one thing we need to understand
14:46 Presenter: in order to understand the kind of risks
14:48 Presenter: that these applications expose
14:49 Presenter: is how are they being developed?
14:52 Presenter: So what is the SDLC?
14:55 Presenter: DLC look like for these low-code apps.
14:57 Presenter: And so let me show you an example of one application.
15:00 Presenter: And this will kind of play out in the background,
15:04 Presenter: but this is a very kind of silly example.
15:06 Presenter: What I’m doing here is essentially
15:08 Presenter: I’m trying to fix my own problem.
15:10 Presenter: In my organization, we’re using Slack.
15:12 Presenter: And there’s this feature in Slack
15:14 Presenter: where somebody can mention you on a public channel.
15:16 Presenter: And then there’s this,
15:18 Presenter: you are expected to reply really quickly, right?
15:21 Presenter: Which is kind of annoying.
15:22 Presenter: So what I’m doing here is I’m using an automation in Zapier
15:26 Presenter: where every time somebody mentions me on Slack,
15:29 Presenter: I’ll change my status as if I’m on a call
15:33 Presenter: because that helps.
15:35 Presenter: And then five minutes later,
15:37 Presenter: I’m going to change my status back to available
15:40 Presenter: so nobody would suspect me.
15:43 Presenter: Okay, this is really cool because it’s showing you
15:47 Presenter: actually a really sophisticated application
15:49 Presenter: that I’m building through Zapier here.
15:52 Presenter: through drag and drop. This entire video takes about
15:54 Presenter: two minutes, but just think
15:56 Presenter: about the level of complexity that this
15:58 Presenter: application
16:00 Presenter: needs to handle. It needs to
16:02 Presenter: reach out to, it needs
16:04 Presenter: to authenticate to Slack. It needs
16:06 Presenter: to store some sort of a secret,
16:08 Presenter: right? It needs to subscribe to
16:10 Presenter: Webhook on the Slack side. It needs
16:12 Presenter: to support API changes
16:14 Presenter: by Slack. It needs to have
16:16 Presenter: a state because this delay step, waiting
16:18 Presenter: five minutes, I mean, somebody needs to
16:20 Presenter: wake up after it. This is a significant
16:22 Presenter: of software. And I’m able to build it
16:24 Presenter: simply with drag and drop.
16:26 Presenter: Now, take
16:28 Presenter: this process that you’re seeing right now
16:30 Presenter: and compare it to the SDLC.
16:35 Presenter: I mean, when I’m
16:36 Presenter: finished here and you say it in a moment,
16:38 Presenter: I’ll have a nice little
16:40 Presenter: pop-up that would say, publish
16:42 Presenter: app. That’s it.
16:44 Presenter: Some of the platforms would even automatically
16:46 Presenter: save applications as you build them
16:48 Presenter: and deploy them to production.
16:51 Presenter: This is a
16:52 Presenter: really, this is a really big challenge
16:54 Presenter: because this means that everything
16:59 Presenter: that we’ve baked into the SDLC
17:01 Presenter: doesn’t really apply here.
17:03 Presenter: It gets pushed out of the way.
17:05 Presenter: Now, one thing I will mention,
17:06 Presenter: which is important,
17:07 Presenter: is that in some cases,
17:08 Presenter: professional development teams
17:09 Presenter: are using low-code with an SDLC,
17:12 Presenter: but they are doing this
17:14 Presenter: kind of despite of existing capabilities.
17:18 Presenter: Their life is not easy at all.
17:22 Presenter: So going into the STLC, again, this is just kind of vanilla STLC.
17:27 Presenter: And this is the typical thing that we have for professional development.
17:30 Presenter: Of course, this could vary a lot, but I’m trying to make a point here about low code.
17:36 Presenter: Let’s compare it to what you’ve just seen.
17:40 Presenter: So there’s no real process here.
17:43 Presenter: There’s a single user that thinks about the problem and then solves the problem.
17:48 Presenter: That means that, one, there’s no exchange of hands between different people.
17:54 Presenter: There doesn’t have to be any planning, any monitoring.
17:58 Presenter: Think about what happens if one of these apps get hacked.
18:02 Presenter: Will your SOC even be able to identify it?
18:05 Presenter: If it was identified, will it be able to actually do something with it, investigate it?
18:10 Presenter: I’m not sure.
18:11 Presenter: And more than that, this entire process is up to the business user.
18:18 Presenter: thing to note here is that this is a good thing. This is the feature that is driving this platform.
18:22 Presenter: This is the reason why we have so many apps, because it’s easy to create those apps. So this
18:26 Presenter: is not going to be easily solved. And one other thing that you could be thinking about to get
18:32 Presenter: yourself off the hook is that this is the platform’s fault. Is that the platforms that are
18:37 Presenter: building, that are allowing users to build these things, they should fix the problem. So I’m not
18:42 Presenter: really sure about that because there’s something called the shared responsibility model. We’ve
18:48 Presenter: You can’t expect a cloud provider to solve your problems for you.
18:50 Presenter: When you build an app on top of a platform,
18:54 Presenter: you’re in charge of that app.
18:56 Presenter: The platform is in charge of making secure building blocks,
18:59 Presenter: allowing you to use the platform in a secure way.
19:02 Presenter: But when you build something, you own that thing,
19:04 Presenter: including the security risk of that thing.
19:07 Presenter: Okay.
19:09 Presenter: And what I’m trying to convince you here
19:12 Presenter: is that this must be our problem
19:15 Presenter: because nobody else would fix it for us.
19:18 Presenter: And with that, the next part or the rest of this talk is going to be focused on the types of problems that we’re seeing when these applications actually get developed.
Detailed Risk Cases — Part 2
19:29 Presenter: And what you’re going to see when we go through the top 10 here is concrete examples of how these applications go wrong.
19:40 Presenter: Now, before I show you the actual list, a few words about this project.
19:48 Presenter: years ago. Today, there’s a community of about 200 people that are across the industry that have
19:52 Presenter: joined kind of the different channels there. These are mostly large enterprises that are part of this
20:00 Presenter: group. And if you’re interested, we’re working on the new version of the 2023 version of the top 10.
20:08 Presenter: So if you’re interested, we’re really looking for feedback reviewers, reach out. We’d be happy to
20:13 Presenter: to kind of get you involved.
20:16 Presenter: This community is not only about the top 10.
20:19 Presenter: We’re also doing things that are more on the red teaming side.
20:22 Presenter: You’ll find a bunch of tools that you can pen test your applications with.
20:26 Presenter: So if you’re interested, either go to the link,
20:28 Presenter: so reach out to me afterwards. I’m happy to direct you.
20:31 Presenter: All right.
20:32 Presenter: This entire top 10 list is built on,
20:37 Presenter: is based on the applications that we’re actually seeing in the wild.
20:40 Presenter: So the applications that were built by business teams inside of the organizations that are part of the OVS group.
20:48 Presenter: This is the top 10.
20:50 Presenter: And the top 10 here is, again, different from the kind of regular top 10 for web apps.
20:55 Presenter: And it’s focused on the business logic that these applications represent.
20:59 Presenter: So it’s not about the specific building block.
21:03 Presenter: This is the platform’s fault.
21:04 Presenter: No, this is all focused on your part, on the organization’s part of the shared responsibility model.
21:11 Presenter: All right.
21:13 Presenter: The first problem that we’re seeing again and again in these local platforms is account impersonation.
21:21 Presenter: Let’s put yourself in the shoes of a local platform that’s trying to expand inside of the enterprise.
21:29 Presenter: Again, without asking for permission.
21:30 Presenter: What would be the number one thing
21:32 Presenter: that would make this graph that we saw earlier
21:36 Presenter: kind of not exist,
21:38 Presenter: that would block this graph,
21:39 Presenter: that would block this growth?
21:40 Presenter: The number one thing that would block you
21:42 Presenter: is permissions, right?
21:45 Presenter: If a user has to ask for permission
21:47 Presenter: every time they create an app,
21:49 Presenter: you would never see this growth.
21:50 Presenter: That would never happen.
21:52 Presenter: So how do you circumvent that?
21:53 Presenter: How do you allow somebody from the HR team
21:56 Presenter: to build an app without asking for a service account?
22:00 Presenter: You allow them to use their own identity.
22:04 Presenter: And so the way that these platforms work, the way that these platforms go around this
22:08 Presenter: problem is that they actually copy the user’s refresh tokens and then replay them as part
22:14 Presenter: of the app, which means that actually they are completely breaking the OAuth model or
22:19 Presenter: the permission model that we’re used to inside of the organization.
22:23 Presenter: Many of these integrations are actually built on top of user impersonation.
22:27 Presenter: So we use the logs in, I copy their token and then I replay it.
22:30 Presenter: allow that user to share that token, but we’ll see it in a moment. Now, one other thing that
22:35 Presenter: typically happens is that when somebody builds an application, it could be an important application,
22:40 Presenter: a useful application, they embed their own identity within that application through these
22:45 Presenter: refresh tokens. And now when I share this application with you, you can use it, but
22:50 Presenter: underlying you’re using my own identity. Now, who cares, right? It works. Well, let me show,
22:57 Presenter: let me share a story with you of what could happen.
22:59 Presenter: So this is a real story where a customer care team
23:02 Presenter: in a large organization,
23:04 Presenter: they basically had a problem
23:06 Presenter: where people didn’t have access
23:08 Presenter: to the right information about customers
23:12 Presenter: when they were part of a support ticket.
23:16 Presenter: And so the way that they saw this
23:17 Presenter: is that they created an application
23:18 Presenter: that used somebody from the customer care team
23:23 Presenter: used their own user to go to the customer.
23:27 Presenter: and fetch information about that specific customer.
23:30 Presenter: And they did bake role-based access control into the app itself.
23:33 Presenter: So the app only exposes the customers that you’re related to.
23:40 Presenter: So employees are happy because they can provide more information.
23:45 Presenter: They can do their job better.
Data Leakage & Authorization Issues — Part 1
23:47 Presenter: Customers are happy because they get better service.
23:49 Presenter: Customer care team is happy because they fixed their problem.
23:52 Presenter: Who’s not happy?
23:54 Presenter: The SOC.
23:57 Presenter: from the SOC’s perspective, right?
23:59 Presenter: This is not an app.
24:01 Presenter: This is just, I don’t know,
24:03 Presenter: scraping inside of the organization.
24:05 Presenter: This is a bunch of different requests
24:08 Presenter: across the enterprise,
24:09 Presenter: going through multiple queries,
24:11 Presenter: multiple IPs, different across time,
24:14 Presenter: that are using the same credentials,
24:15 Presenter: which are admin credentials to the database, right?
24:17 Presenter: And this was actually caught
24:19 Presenter: by kind of abnormal activities
24:21 Presenter: that were caught inside the SOC.
24:23 Presenter: And just imagine the SOC analyst
24:27 Presenter: handle this. It took them some time to find that this is actually an application and who’s built
24:33 Presenter: this application. And then the stock analyst reached out to the person on the customer care team.
24:37 Presenter: Imagine that conversation, right? Not an easy conversation. Now, of course, it’s obvious why
24:45 Presenter: this is a problem, right? You are baking in an identity to an application and everybody can use
24:51 Presenter: that identity underlying.
24:53 Presenter: And even though in this specific case,
24:55 Presenter: role-based access control was baked into the app,
24:58 Presenter: in many cases that doesn’t happen.
25:00 Presenter: Some platforms even have a notion
25:02 Presenter: that they call implicit sharing,
25:04 Presenter: which essentially means when I share an application with you,
25:07 Presenter: you get direct access to the underlying data sets.
25:10 Presenter: Even if I revoke access to the app afterwards,
25:14 Presenter: you still get access to those data sets.
25:16 Presenter: So let’s see where that can take us.
25:17 Presenter: And this would be the second thing, the second top 10 here, which is about authorization.
25:23 Presenter: Now, problems with authorization, they’re not new.
25:28 Presenter: There’s nothing new about low-code here.
25:29 Presenter: The only thing that’s new is that this has become much, much, much easier
25:35 Presenter: because low-code platforms are essentially doing credential sharing as a service.
25:39 Presenter: They are providing you with a service that allows you to share your authentication,
25:44 Presenter: to share your identity with other users within your organization.
25:48 Presenter: snapshots of different platforms you’re seeing, Power Automate by Microsoft, Zapier and Wrocato,
25:53 Presenter: this is not picking them to them specifically. Others are doing this as well. They all have a
25:58 Presenter: notion called kind of a default environment or a default folder. And in this default environment,
26:06 Presenter: what you’ll find is credentials, connections that have been shared across your entire organization.
26:11 Presenter: And when I say across your entire organization, I mean everybody in your AAD tenant, that would
26:17 Presenter: example, and this is a single click away when you create those connections. Now, what can a
26:22 Presenter: connection be? You can see, you might be able to see on the slides here a few examples, but in many
26:27 Presenter: organizations, we’re seeing connections to people’s own Outlook and Teams users. We’re seeing FTP
26:34 Presenter: servers, SQL servers. This could also reach out to on-prem through gateways. And so this is just
26:41 Presenter: basically a lateral movement waiting to happen, right? If I get access to any user in the
26:47 Presenter: I can reach out to those platforms and just find those connections that are waiting for me to use.
26:53 Presenter: And we actually have a bunch of tools that could help you identify this within your organization.
26:57 Presenter: I’ll give links to them afterwards.
27:00 Presenter: One other thing that we’re seeing with authorization is basically that people are,
27:07 Presenter: API permissions can be somewhat difficult, especially if you’re not an expert
27:12 Presenter: or if you’re not a professional developer.
27:14 Presenter: And then in many cases, what we’re seeing is that all of the users of an app get provisioned with the same permissions, admin level permissions.
27:22 Presenter: But then they hide the different screen, the administrative screens on the UI side, on the client side.
27:27 Presenter: This is very common, for example, with Salesforce development.
27:30 Presenter: We’ve seen this again and again.
27:31 Presenter: And so here, of course, the problem is obvious, right?
27:34 Presenter: But this is not something that you think about unless you’re aware of the risks.
27:39 Presenter: and we’ve been
27:42 Presenter: kind of in recent years
27:44 Presenter: we’ve gotten a long way
27:46 Presenter: with professional developers becoming
27:48 Presenter: better equipped to
27:49 Presenter: work around security. Business users
27:51 Presenter: are not there. I’m not sure we can expect them
27:53 Presenter: to be there.
27:55 Presenter: Okay, let’s go to the next one.
27:58 Presenter: There are
27:59 Presenter: multiple ways in which we are trying
28:02 Presenter: as enterprises to
28:03 Presenter: block data leakage outside of the org
28:06 Presenter: and one of the things that we’ve been trying
28:09 Presenter: is emails going outside of the organization, right?
28:12 Presenter: So, for example, one very popular thing to do for all of us
28:18 Presenter: is to get the corporate email invites
28:22 Presenter: to our personal Gmail account
28:24 Presenter: because it’s much more comfortable.
28:26 Presenter: Now, organizations are trying to combat, to block this,
28:31 Presenter: and the way that they do it could be through DLP solutions,
28:34 Presenter: could be through something on the email server,
28:37 Presenter: But here’s what’s happening with local platforms.
28:40 Presenter: Instead of forwarding an email,
28:43 Presenter: instead of doing anything that would work over the network,
28:47 Presenter: which would allow a network perimeter appliance to help you,
28:51 Presenter: they are simply connecting with one hand,
28:53 Presenter: with one account to the corporate account,
28:56 Presenter: and with the other hand, with another account
28:58 Presenter: to the personal Gmail account,
28:59 Presenter: and then copying the content.
29:01 Presenter: And this copy operation is being done
29:06 Presenter: form that is owned by the vendor. You don’t have an agent there. There’s no way for you to monitor
29:10 Presenter: it. So again, this is a clear way to export data outside of the organization. There hasn’t been a
29:15 Presenter: single org that I worked with that didn’t have some form of this happen inside of the org.
29:21 Presenter: This could be about email. This could be about moving data between different drives, so SharePoint
29:30 Presenter: and Google Drive, for example. And we also see in many cases that people could build a useful
29:36 Presenter: just use the wrong database
29:39 Presenter: as the database of that application.
29:41 Presenter: Instead of storing it in a corporate database,
29:43 Presenter: they’ll store it in their own personal OneDrive,
29:45 Presenter: for example, or Excel sheet.
29:48 Presenter: One other thing that could happen
29:50 Presenter: is that these applications could be used
29:52 Presenter: to do malicious things.
29:54 Presenter: So for example,
29:55 Presenter: this is an example of a ransomware
29:58 Presenter: for a specific SharePoint site.
29:59 Presenter: So I’m iterating over the entire SharePoint site
30:02 Presenter: and for each file,
30:03 Presenter: I’m simply encrypting that file
30:06 Presenter: function that is provided by the platform and overriding it within the site.
30:11 Presenter: Now, SharePoint has backups, but this same thing could happen on an on-prem machine through
30:18 Presenter: the on-prem connection of those types of platforms.
30:20 Presenter: And this is just one case, but we see in many cases where these platforms by mistake cause
30:26 Presenter: harm.
30:27 Presenter: So there might be conflicting automations that are overriding some files and then things
30:31 Presenter: get changed and you need to walk your way through those types of applications again with
30:35 Presenter: no visibility into it.
30:38 Presenter: one other problem that we’re seeing is authentication and secure communication.
30:42 Presenter: And this is,
30:43 Presenter: this is kind of a silly one,
Data Leakage & Authorization Issues — Part 2
30:45 Presenter: but the power of these platforms is based on the fact that they can connect
30:49 Presenter: across your enterprise.
30:51 Presenter: They come built in with hundreds of different connectors that connect to
30:55 Presenter: SAS and on-prem and others and other places as well.
30:57 Presenter: And when you create those connections,
31:00 Presenter: you as the business user,
31:02 Presenter: you’re in charge of configuring them correctly.
31:04 Presenter: So one thing that we’ve seen,
31:06 Presenter: of weird because this is something we thought we solved already, is the connections to FTP
31:11 Presenter: that are using FTP rather than FTPS.
31:14 Presenter: And again, this is up to the user to the side, the business user.
31:18 Presenter: They can’t really do it on their own.
31:21 Presenter: Okay, let me show you another thing which is pretty common, which is misconfiguration.
31:28 Presenter: This has been a huge thing in cloud for recent years.
31:32 Presenter: And one of the things that you should be thinking about when you think about misconfiguration, as an example, is the open S3 bucket problem with AWS.
31:42 Presenter: So AWS has recently changed the default and made it very difficult for you to open up these buckets.
31:48 Presenter: But we still have open buckets with private corporate information out there because people are making mistakes.
31:55 Presenter: And so it’s not only about the default.
31:56 Presenter: It’s also about helping people not make mistakes.
32:00 Presenter: And so let me show you how this pops up again with low code.
32:04 Presenter: This is an example from Microsoft’s platform.
32:07 Presenter: They have something called Portal Apps,
32:09 Presenter: which is an application that is basically creating a web app for you.
32:13 Presenter: And it allows anonymous users,
32:17 Presenter: so users that are unregistered, not logged in,
32:19 Presenter: to go into the website because, well, it’s a website.
32:23 Presenter: Another feature that it has is an API.
32:26 Presenter: is basically an API endpoint that it sets up for you
32:29 Presenter: that allows you to query all of the different tables
32:32 Presenter: behind this application.
32:35 Presenter: Now, the problem was that the default configuration
32:37 Presenter: was that every user, including anonymous users,
32:41 Presenter: could access every table behind this application
32:45 Presenter: through this API.
32:46 Presenter: And this was actually a problem identified, again,
32:50 Presenter: about a year and a half ago, where the default was like this.
32:53 Presenter: And so it was very easy to find the information that should not be exposed to everyone just through randomly querying those applications.
33:02 Presenter: And so even though the problem has been fixed by Microsoft, the default setting has been changed, this is still happening.
33:09 Presenter: So let me show an example from last year.
33:11 Presenter: And this is a real example.
33:12 Presenter: This is a portal for a company, a financial industry company in the US.
33:17 Presenter: You can see we found this specific portal for that company.
33:22 Presenter: I’ll share with you in a moment how.
33:25 Presenter: And then when you query this API,
33:27 Presenter: you get a list of all of the tables that you can query through the API.
33:30 Presenter: So the default table doesn’t have anything interesting.
33:34 Presenter: Entity form set is just form submissions.
33:36 Presenter: Global variables is kind of interesting, right?
33:39 Presenter: So, of course, it has authentication tokens to Azure and to other services.
33:46 Presenter: of course it’s close to the specific
33:48 Presenter: company where we find this but
33:51 Presenter: the main problem
33:52 Presenter: here and maybe I’ll go back a few
33:54 Presenter: slides so you can figure this out on your own
33:56 Presenter: look at this domain name
33:58 Presenter: all of these applications are
34:00 Presenter: stored in
34:01 Presenter: are served in different subdomains
34:04 Presenter: of this domain so just enumerate this domain
34:07 Presenter: enumerate these different subdomains
34:08 Presenter: go to this endpoint and it’s very
34:10 Presenter: easy to find those configurations
34:13 Presenter: misconfigurations are very much
34:14 Presenter: predictable, which makes this a huge problem.
34:19 Presenter: Okay.
34:20 Presenter: Another thing that we see pop up with the local platforms is injection attacks or more injection
34:28 Presenter: surface.
34:28 Presenter: Now, this could be a tricky one because platforms would tell you that injection has been solved
34:33 Presenter: because you’re using widgets that are provided by the platform.
34:35 Presenter: But if you take input from a user and you plug it into a SQL query that goes out to your SQL server and you don’t sanitize it on the way, then you have created an injection surface.
34:51 Presenter: And again, because this is something that business users are doing or that people that are not part of the security umbrella are doing, then you’re not in a really good position to help them catch it.
35:02 Presenter: Another problem that is surfacing here again is the supply chain.
35:06 Presenter: the only reason why low code is successful
35:08 Presenter: is because there’s a bunch of tools
35:11 Presenter: you can pick up and use from a marketplace
35:14 Presenter: in order to build your application.
Supply Chain, Logging, and Closing — Part 1
35:16 Presenter: There are widgets, there are connectors,
35:18 Presenter: which are kind of wrappers around APIs.
35:21 Presenter: There are different backend operators that you could use.
35:25 Presenter: All of those things,
35:26 Presenter: some of them are built by the platform themselves,
35:29 Presenter: but all of the large platform vendors have a marketplace.
35:33 Presenter: if you think that they are doing
35:36 Presenter: that they are completely owning the risk
35:38 Presenter: of all of the components in their marketplace
35:40 Presenter: you’re absolutely wrong
35:41 Presenter: they might do a single review
35:44 Presenter: but they cannot review every change of each one of those widgets
35:47 Presenter: and also in many cases
35:48 Presenter: the way in which you’re using those different cell party widgets
35:52 Presenter: is that you can just pick them up from GitHub or something
35:55 Presenter: like a zip file
35:56 Presenter: and then you upload it somewhere
35:57 Presenter: there’s no hashing, there’s nothing
36:00 Presenter: so the problem of
36:03 Presenter: supply chain attacks is very difficult to find
36:10 Presenter: and actually identify within those local platforms.
36:12 Presenter: And again, it’s baked in because local platforms
36:15 Presenter: without third-party widgets
36:17 Presenter: would really don’t have a lot of value in them.
36:21 Presenter: Let me show you another kind of example
36:23 Presenter: that we’re seeing a lot.
36:25 Presenter: And this is about sensitive data,
36:27 Presenter: sensitive data and sensitive secrets.
36:33 Presenter: Here’s an example, an app that uses some sort of sensitive data.
36:38 Presenter: A user submits that sensitive data to the app,
36:40 Presenter: and then the app stores the sensitive data on a database in plain text.
36:45 Presenter: This is kind of funny, and again, not new,
36:48 Presenter: but because business users are building these applications,
36:50 Presenter: how would they know how to store credit cards?
36:52 Presenter: It’s not really their role.
36:54 Presenter: So let me show you, let me share a specific example.
36:57 Presenter: This is an HR team at a large IT company.
37:00 Presenter: Basically, they wanted to do a giveaway campaign
37:03 Presenter: where people can donate money to charity.
37:06 Presenter: So they created a small application that did a very simple thing.
37:10 Presenter: You register to the application, you provide your credit card,
37:13 Presenter: and you choose the charity you’d like to donate to,
37:16 Presenter: and the company will donate as well.
37:18 Presenter: Now, the credit cards that were collected there were stored,
37:22 Presenter: A, in plain text, B, in an environment which was kind of a development environment
37:27 Presenter: shared across the entire organization.
37:30 Presenter: So again, this is very cool that business users are able to do this, but this is kind of a problem.
37:35 Presenter: And by the way, they found this when compliance auditors started asking questions, which is kind of a difficult place to be at.
37:43 Presenter: And we are seeing this thing about kind of sensitive data that’s being handled by these applications a lot.
37:50 Presenter: And again, because these platforms are built, these local platforms are built on top of SaaS platforms that contain business data,
37:58 Presenter: it’s very difficult to create those distinctions to make sure that these applications are not touching business data, for example.
38:07 Presenter: One other thing that is clear is that most of these applications are built outside of IT’s eye or control.
38:15 Presenter: There are so many cases where somebody builds a successful application, other people are using them, and then this person leaves the organization.
38:23 Presenter: Okay, what happens now?
38:24 Presenter: This application remains, I mean, it’s used until it doesn’t work anymore.
38:30 Presenter: And then who would you call?
38:32 Presenter: What would happen if this application gets hacked?
38:34 Presenter: Who would own it?
38:35 Presenter: I mean, this is a really difficult situation.
38:39 Presenter: And this is because we, as the people that are in charge of kind of securing the organization,
38:44 Presenter: we’re really not aware of them.
38:45 Presenter: One of the key things that I see people try to do here is focus on applications that become viral within the organization.
38:53 Presenter: So focus on those apps that are not used by one user or a couple of users, but used by a lot of different users within the org.
39:01 Presenter: And the last problem that I’ll mention here is logging and monitoring.
39:06 Presenter: So it’s funny, but there are kind of two separate problems here, which are kind of the opposite.
39:12 Presenter: One is that in many cases, there are no logs at all.
39:15 Presenter: So you won’t find, or the logs are not available to the right people.
39:20 Presenter: So again, just think about whether you can,
39:22 Presenter: if something happens with one of these applications,
39:25 Presenter: whether you can actually create an investigation to find out what happened,
39:28 Presenter: who is logging into these applications,
39:30 Presenter: what data did they provide to those users?
39:33 Presenter: So those things don’t really exist.
39:35 Presenter: But on the other hand, some of these actual components,
39:39 Presenter: for example, these automations, have a habit of recording everything.
39:45 Presenter: I mean all of the data that goes through those automations.
39:49 Presenter: And so one of the issues that we’re seeing is that,
39:52 Presenter: let’s say I build an application
39:55 Presenter: that allows you to check your email or something.
39:58 Presenter: Okay, now you can use the application,
40:02 Presenter: but as the builder of that application,
40:04 Presenter: I can access the logs that are available to that application,
40:08 Presenter: which can include the actual data that goes through the app.
40:12 Presenter: Okay, which is again a very clear path
40:15 Presenter: to privilege the escalation of one user
40:19 Presenter: to be able to view things by other users.
40:21 Presenter: And actually, previously,
40:25 Presenter: earlier this year at DefCon,
40:26 Presenter: I showed how this specific capability
40:28 Presenter: could be used to move laterally across the organization.
40:32 Presenter: All right.
40:33 Presenter: So we have seen,
40:36 Presenter: let’s talk about what we’ve seen so far.
40:39 Presenter: We’ve seen that low-code, no-code
40:41 Presenter: is rapidly growing within the organization.
40:43 Presenter: and chances are it’s already there in your org.
40:47 Presenter: And I’m not saying this as,
40:49 Presenter: you shouldn’t be worried about this.
40:51 Presenter: You should bring it under the security umbrella.
40:54 Presenter: I mean, security, business users are,
40:56 Presenter: in many cases, you’ll find that there are teams
40:59 Presenter: that have already started developing
41:00 Presenter: critical applications on these platforms
41:02 Presenter: and they are scared because nobody’s helping them
41:05 Presenter: to make sure they’re doing the right thing.
41:07 Presenter: There’s a huge opportunity here for us
41:10 Presenter: to be part of that conversation.
41:13 Presenter: we saw that there’s missing SDLC.
41:15 Presenter: In some cases, there is some SDLC,
41:17 Presenter: but in many cases, you’ll find none.
41:19 Presenter: And I really encourage you to look at the OWASP top 10.
41:23 Presenter: There are a bunch of more examples
41:24 Presenter: that I haven’t shared here already.
41:26 Presenter: And actually, the new version that we’re going to share
41:30 Presenter: is going to be much deeper.
41:31 Presenter: One of the things that we are working on
41:33 Presenter: is having those top 10 written in a way
41:36 Presenter: that you can actually give your business users
41:38 Presenter: and they will understand
41:39 Presenter: to help them be closer to the security mindset.
41:44 Presenter: The opportunities for you to take,
41:46 Presenter: and this might be the most important thing to take out of the slides,
41:50 Presenter: out of this talk,
41:52 Presenter: there’s a huge opportunity for you to be the champion of this space
41:55 Presenter: within your organization.
41:57 Presenter: AppSec needs to be part of the low-code, no-code conversation
42:00 Presenter: or the business development conversation.
42:02 Presenter: We are seeing organizations that are creating security frameworks
42:05 Presenter: or basically extending the secure development policies
42:09 Presenter: they have two business users.
42:11 Presenter: And of course, there’s a lot of need to think about
42:14 Presenter: what exactly do you want to build there?
Supply Chain, Logging, and Closing — Part 2
42:16 Presenter: What use cases are approved?
42:18 Presenter: How are you checking those use cases?
42:21 Presenter: How are you providing galleries
42:23 Presenter: for those users to build correctly?
42:26 Presenter: But instead of just thinking,
42:29 Presenter: so they don’t need to think about security.
42:31 Presenter: They can just continue building,
42:32 Presenter: but you protect them along the way.
42:35 Presenter: If you’re interested, please reach out.
42:38 Presenter: and I think we have some time for questions
42:40 Presenter: so thank you very much
42:49 Presenter: I might do this so we have light
42:54 Presenter: thank you, I’ll be coming around
42:55 Presenter: and let’s see, okay now I can see
43:00 Presenter: you raised your hand?
43:01 Presenter: okay, come on
43:04 Presenter: wait, wait, I’m going to give you the microphone
43:10 Presenter: So something that came to mind for me was when we’ve seen people whose, say, Office 365 email has been compromised and the bad guys tend to create outlook rules and things like that to forward emails for business email compromise and things like that.
43:27 Presenter: I was wondering if you’ve seen any instances where these automations were used to do that as well, like the email things that you suggested.
43:34 Presenter: So, unfortunately, yes. About three years ago, Microsoft published a report where a single organization was attacked by something like four different malware groups.
43:45 Presenter: And defenders were looking to clear the network out of malware for like six months.
43:50 Presenter: And they weren’t able to find what was going on.
43:55 Presenter: After six months, they found a single power automation.
43:59 Presenter: They did a very simple thing. It was running under administrative permissions.
44:04 Presenter: It used the e-discovery tools by Microsoft to find sensitive information, secrets, whatever it could, across the organization, store all of them, and send them to an HTTP endpoint.
44:16 Presenter: And this was a single automation that, I mean, just trying to find this automation took so much time.
44:22 Presenter: And so this is, I can share a link afterwards if you’re interested.
44:26 Presenter: Shoot me an email or on Twitter.
44:29 Presenter: But this was actually a long time ago.
44:34 Presenter: We’ve seen this happen mostly as mistakes, people that are making mistakes and just moving that outside of the org.
44:45 Presenter: Thank you.
44:46 Presenter: On to the next question.
44:52 Presenter: Any ideas on a strategy for how to detect and find these things in your organization?
44:58 Presenter: Yes.
44:59 Presenter: So I do have one optimistic message here.
45:03 Presenter: we have to remember that these things
45:07 Presenter: I mean data that was
45:09 Presenter: these low code applications are replacing
45:11 Presenter: what you can call copy and paste integration
45:14 Presenter: people have been moving files from one place to another
45:17 Presenter: since forever and we’ve been trying to address it with DLP solutions
45:20 Presenter: and other things for a long time and we haven’t been successful at all
45:23 Presenter: but now when business users are using these low code
45:26 Presenter: no code platforms there’s somebody you can ask
45:29 Presenter: tell me you can go to the platform
45:32 Presenter: and ask what are all of the applications that are available in your platform
45:36 Presenter: that have been built on top of your platform.
45:38 Presenter: Now, of course, it does require you to understand what these applications are doing,
45:43 Presenter: to scan, for example, the definitions of those applications
45:47 Presenter: to actually figure out what data they’re attaching.
45:49 Presenter: And we are seeing organizations that are actually going through those processes.
45:54 Presenter: So you can do it.
45:55 Presenter: You can automatically scan those applications, find inventory them,
45:59 Presenter: find vulnerabilities, collect logs.
46:02 Presenter: of work that you need to do in order to do that, you do have an API for some of it.
46:08 Presenter: So you do have, for example, an API to query what all of the applications that exist that
46:13 Presenter: is much more than we had when businesses were just copying files.
46:19 Presenter: Thank you.
46:21 Presenter: We have four minutes more left for questions.
46:24 Presenter: Anybody else?
46:28 Presenter: Thank you.
46:29 Presenter: it seemed like one of the largest issues you mentioned with this was role-based authentication
46:34 Presenter: um it seems like largely that’s because it’s operating outside of the existing structures we
46:42 Presenter: have for auditing that you mentioned sock i believe do you think that we would still see benefit
46:49 Presenter: in the low code no code solutions if we force them to go through the more standard process
46:55 Presenter: of role-based authentication?
46:58 Presenter: And how do you see that working
46:59 Presenter: when currently they seem to be working
47:02 Presenter: around current authorization structures?
47:06 Presenter: Do you think, and I know you said
47:08 Presenter: that we can’t rely on them to,
47:10 Presenter: or rely on the tools to fix the problems for us.
47:15 Presenter: Do you think it’s reasonable
47:16 Presenter: that they should be working
47:17 Presenter: within current structures such as OAuth?
47:20 Presenter: So I think all of the platforms
47:25 Presenter: you to build your applications and connect to things with service accounts rather than users,
47:31 Presenter: which would be the best case scenario, right? Because then you can provision those accounts,
47:36 Presenter: you can monitor them, et cetera. The problem is that this means that somebody needs to ask for
47:42 Presenter: permissions, which creates a roadblock, which means that the applications won’t get fully adopted,
47:47 Presenter: adopted, which means in my, at least in my view, that it would never really happen.
47:54 Presenter: I mean, again, these capabilities are available.
47:57 Presenter: In some platforms, people are actually using service accounts, but enforcing the use of
48:02 Presenter: service accounts, I don’t see a way for this to work together with the exponential growth
48:09 Presenter: or with the quadratic growth that we’ve seen earlier.
48:13 Presenter: There are cases, and connecting this to the previous question, one of the things that I do see enterprises do is that they make sure that for some use cases, so for example, if you’re touching business-sensitive data, if you’re touching credit cards, you have to use a service account.
48:30 Presenter: But then you need some way to actually enforce that rule.
48:39 Presenter: Thank you, and this will be our last question.
48:42 Presenter: We have one minute left.
48:45 Presenter: Yeah, somebody who is kind of dealing with a new low-code environment coming in, I echo everything you said.
48:55 Presenter: One of the things in the security organization, we sort of caught it sort of late into the adoption cycle.
49:01 Presenter: and one of the things that we’ve had to do is basically say that only modules that have been vetted
49:10 Presenter: are allowed to be brought into our organization so something equivalent to artifactory kind of a
Supply Chain, Logging, and Closing — Part 3
49:16 Presenter: model and we’ve also had to work with the vendor applying heavy pressure to allow our sonar cube
49:26 Presenter: rules, for example, be applied.
49:29 Presenter: And
49:31 Presenter: just as a normal
49:32 Presenter: sort of thing with hard
49:34 Presenter: guard rail mechanisms, it was
49:36 Presenter: something that the no-code, low-code
49:38 Presenter: vendor was like very, very, very
49:40 Presenter: grumpy about. But it’s
49:42 Presenter: something that we’ve really twisted the screws
49:44 Presenter: on. So we are,
49:46 Presenter: you know, I’m not going to say what my organization is
49:48 Presenter: obviously, but it’s something that
49:50 Presenter: everything you said is absolutely 100%.
49:52 Presenter: And we’ve been applying screws on that stuff.
49:56 Presenter: I think that one of the mistakes I think we should avoid,
50:02 Presenter: I mean, we must push the vendors to be better.
50:06 Presenter: However, we need to understand that there’s an entire ecosystem
50:11 Presenter: that needs to be built here, right?
50:13 Presenter: When you build a normal app, a ProCode app,
50:17 Presenter: you have shift left, you have runtime monitoring,
50:21 Presenter: you have network perimeter,
50:23 Presenter: you have a bunch of things that are helping you prevent mistakes
50:26 Presenter: prevent attacks. In no code, you don’t
50:28 Presenter: really have all of them, and
50:30 Presenter: vendors would solve everything for us, but
50:32 Presenter: vendors need to make it easier for us
50:34 Presenter: to actually solve those problems.
50:36 Presenter: I know we’re out of time. Thank you very much.
50:38 Presenter: I’ll stay here for questions,
50:40 Presenter: and if you can’t catch me here,
50:42 Presenter: reach out on Twitter. Thanks.
50:44 Presenter: applause