All talks

RSAC 2023 · 2023/04

Credential Sharing as a Service: the Dark Side of No Code

Loading presentation…

Read the abstract and transcript

Abstract

Low-code apps have become a reality in the enterprise, with surveys showing that most enterprise apps are now built outside of IT and lacking security practices. Unsurprisingly, attackers have figured out ways to leverage these platforms for their gain. This talk will demonstrate a host of attack techniques found in the wild, where low-code apps are abused during every step in the cyber kill chain.

Official conference abstract

Transcript

AI generated from recording.

Opening Remarks and Context Setting

00:01 Presenter: Thank you. Thank you so much. So, hi, everyone. First of all, I’d like to say thank you for staying with me. This is an interesting slot, but I think we have the opportunity to have a real discussion here today. So please feel free. Don’t wait till the end of the slides with questions. If you have any questions during the talk, just raise your hand. We can make it a discussion. It would be much more interesting.

00:30 Presenter: What we’re going to do today would be significantly different than what you’ve seen throughout

00:39 Presenter: this conference, because we are going to talk about a section of risk, of security risk,

00:47 Presenter: that is usually left underprotected.

00:51 Presenter: And so before I go deep into that, briefly about myself, my name is Michael.

01:00 Presenter: the OWASP Low-Code, No-Code Top 10 project,

01:03 Presenter: which is an OWASP project dedicated to Low-Code, No-Code.

01:06 Presenter: You can look it up, you’ll find plenty of examples.

01:09 Presenter: There’s a growing community of over 200 people

01:12 Presenter: that are actually part of this group.

01:15 Presenter: I co-founded a company called Xenity a couple of years ago.

01:18 Presenter: Xenity is focused on security for Low-Code, No-Code.

01:22 Presenter: It’s basically an application security company in this space.

01:26 Presenter: Previously, I spent several days at Microsoft,

01:30 Presenter: as part of their CTO office division.

01:34 Presenter: I work both on the blue side and the red side,

01:37 Presenter: so I gave a couple of talks at Defcon about this space,

01:40 Presenter: and I also do, but actually most of my work

01:44 Presenter: is helping organizations protect themselves.

01:46 Presenter: What we’re going to see today is,

01:49 Presenter: first of all, I’m going to try and make sure

01:51 Presenter: we are all on the same page on what low code and no code is,

01:54 Presenter: and why is it important, why is it important for us to put our time in there.

02:00 Presenter: But also we’re going to see just how far hackers can get when they are targeting these kinds of services.

02:08 Presenter: Because it’s important for us to actually be able to convince ourselves and others that this is an important area to invest in.

02:17 Presenter: So after kind of this short disclaimer by RSA, this is what we’re going to do in this session today.

02:24 Presenter: start by making sure we are on the same page

02:27 Presenter: on what low-code, no-code actually is.

02:29 Presenter: Then we’ll discuss how low-code applications get built.

02:33 Presenter: We’ll try to figure out what does the SDLC look like

02:36 Presenter: for low-code, no-code.

02:39 Presenter: After that, to share with you a bunch of attacks

02:42 Presenter: that we’ve observed in the wild.

02:44 Presenter: This is through, this comes from both observability

02:50 Presenter: that my company has and that the OWASP project provides.

02:54 Presenter: We go through concrete examples of how hackers have been using those platforms to get what

03:02 Presenter: they want, basically, from the enterprise.

03:04 Presenter: And of course, we’re going to finish with a few resources that you could actually use

03:10 Presenter: to be in a better situation or to take this further inside of your organization.

03:17 Presenter: All right.

03:19 Presenter: So let’s start with understanding what low-code, no-code actually is.

03:24 Presenter: This is kind of a silly joke, but actually I think it captures pretty well why low-code,

03:31 Presenter: no-code is important and why we’re seeing it pop up again and again here.

03:38 Presenter: I mean, IT will never be able to accomplish everything that the business needs.

03:45 Presenter: And we know that with the pace of change and things that are happening all around us, it’s really impossible for IT to keep up.

03:53 Presenter: The people that are best equipped to move the business forward are, of course, business users.

03:58 Presenter: But they are often the ones that are less empowered than the IT team.

04:05 Presenter: And low-code, no-code really addresses this at its core.

04:08 Presenter: because it’s about empowerment of everybody

04:11 Presenter: to build applications faster

04:14 Presenter: and in a way that requires less technical capabilities.

04:17 Presenter: Now, of course, local is also used by professional developers.

04:20 Presenter: We’ll touch on that as well.

04:22 Presenter: But it’s all about enablement.

04:24 Presenter: It’s all about making it easier to solve business use cases.

04:28 Presenter: If this sounds familiar,

04:30 Presenter: then, well, it’s because local is just one point

04:34 Presenter: in a very long trend of IT decentralization.

04:41 Presenter: Over the years, there have been multiple tools

04:43 Presenter: that were used to empower business users

04:48 Presenter: and to provide more power in the hands of basically everyone.

04:52 Presenter: So Excel or Microsoft Office is a great example.

04:55 Presenter: How many jobs are entirely based on Excel today?

04:59 Presenter: So many of them.

05:00 Presenter: And even, I mean, the one tool that I have been using across throughout my career has been Excel.

05:06 Presenter: And I kind of started knowing nothing, and now I know some things, but Excel is still there because it’s a great tool.

05:14 Presenter: And low-code, no-code is really another point on this evolution.

05:18 Presenter: Now, of course, Excel things came with things like macros, which are, up until today, are kind of close friends on the security side.

05:25 Presenter: But it’s important to understand that while this is new, what’s new here is that low-code,

05:32 Presenter: no-code is really successful.

05:34 Presenter: It’s really being, business users are actually building this to build, are actually using

05:40 Presenter: this to build meaningful things.

05:42 Presenter: But the idea behind it is not new though.

05:46 Presenter: This is something that we’ve been experiencing since forever.

05:48 Presenter: And of course, as security teams, most of our programs are focused on what our developers

05:56 Presenter: rather than what our business users are building.

05:59 Presenter: And we’ll see in a moment where that could lead us.

06:02 Presenter: So one thing that’s really important, I think,

06:05 Presenter: for us to have a security discussion on low-code, no-code,

06:08 Presenter: is first of all to understand the business value.

06:11 Presenter: So we are all on the same page on what types of applications

06:14 Presenter: are actually being built with low-code, no-code,

06:16 Presenter: and the fact that they are important for our business to operate.

06:19 Presenter: So let me show you a few real-world examples.

06:22 Presenter: Here’s one.

06:23 Presenter: This is an application by Microsoft.

06:25 Presenter: When you go and visit Microsoft offices physically,

06:29 Presenter: you need to provide a vaccine proof.

06:35 Presenter: And this is basically, this is a website.

06:37 Presenter: You go in, then you log into the website.

06:40 Presenter: After that, you need to upload your COVID certificate.

06:43 Presenter: So this is a pretty meaningful app, right?

06:46 Presenter: So it has a login.

06:47 Presenter: It, of course, handles health data.

06:49 Presenter: it’s important for them to get it right.

06:53 Presenter: So this is one interesting example.

06:56 Presenter: Let me show you another.

06:59 Presenter: This comes from a customer use case by Slack using Orkato,

07:05 Presenter: where they are basically sharing that they’ve automated

07:09 Presenter: their entire order-to-cache processes through Orkato,

07:14 Presenter: through low-code automation, which is amazing, right?

07:17 Presenter: This is a professional development team.

07:19 Presenter: This is heavily used in low code,

07:22 Presenter: but it’s important to understand that this process cannot have any issues with it.

07:28 Presenter: This is about the actual bottom line of the company.

07:32 Presenter: Okay.

07:33 Presenter: Let me show you a different scenario.

07:37 Presenter: This, again, is a use case for Microsoft,

Defining Low‑Code/No‑Code and Its Business Value

07:42 Presenter: but this time it’s a bit different.

07:43 Presenter: So the product marketing team at Microsoft found out that they have different processes to actually release products.

07:53 Presenter: So in order to facilitate one process that everybody could use,

07:58 Presenter: they created an app that basically allowed everybody to go through the steps required to release a product in a very standard way.

08:05 Presenter: The people that have created this app were part of the marketing team.

08:09 Presenter: This was not IT.

08:10 Presenter: And they have created it pretty quickly.

08:13 Presenter: a few days. And you can see the highlighted quote there, that a few months later this

08:18 Presenter: application was the go-to standard for product launches. This is amazing. This shows the

08:24 Presenter: power of low-code. But when we think about the security aspects of it, they will, I mean

08:32 Presenter: you can’t really expect somebody from the business to think about the security aspects

08:38 Presenter: of what’s going on with this application.

08:40 Presenter: Now, one thing that you might have in mind right now in order to get yourself off the hook is thinking that this might not be relevant in your organization.

08:50 Presenter: And I’m sorry to say that, but you don’t really get a choice.

08:56 Presenter: And here’s why.

08:58 Presenter: All of the largest SaaS vendors that most enterprises are using have already incorporated low-code, no-code directly into their services.

09:10 Presenter: And so if you’re using Microsoft, if you’re using Salesforce or ServiceNow,

09:15 Presenter: you will find that while we are still, in some cases,

09:20 Presenter: we are thinking about these things as like point solutions,

09:26 Presenter: specific SaaS solutions.

09:27 Presenter: So you could be thinking about Salesforce as a CRM.

09:30 Presenter: Salesforce is no longer just a CRM.

09:32 Presenter: It’s an application development platform.

09:35 Presenter: And the same is true for ServiceNow and the same is true for Office.

09:40 Presenter: And so if you’re using these types of SaaS platforms

09:44 Presenter: and you’re used to thinking about them

09:46 Presenter: as under the shadow IT prisma,

09:48 Presenter: then you might miss the fact that these are now

09:51 Presenter: closer to cloud than they are to SaaS.

09:55 Presenter: So like cloud is a, so the public cloud is a way

09:59 Presenter: for us to build applications.

10:01 Presenter: It’s a platform to build applications in a,

10:04 Presenter: kind of just making it easier to do that.

10:06 Presenter: This is what’s happening right now with SAS as well,

10:10 Presenter: but instead of being a public cloud

10:14 Presenter: where the developers are professional developers,

10:16 Presenter: this is a business cloud

10:18 Presenter: where the developers are business users.

10:20 Presenter: And we need to think about it that way.

10:22 Presenter: If we will continue to think about SAS

10:24 Presenter: under the shadow of Prisma only,

10:28 Presenter: then we’re going to miss the fact

10:29 Presenter: that real applications get built here.

10:32 Presenter: Now, one important piece here

10:36 Presenter: The people that are building these applications are our users, which makes this our problem.

10:42 Presenter: This is not a problem that the vendors will fix for you because it’s not their part of

10:46 Presenter: the share responsibility model.

10:48 Presenter: When we build an application, we are in charge of securing that application because we are

10:53 Presenter: the only ones that understand the risk appetite of our organization.

10:58 Presenter: And so one thing that’s really important for us to, for you to get out of this talk is

11:06 Presenter: This is one of those scenarios like bring your own device, like mobile security, where

11:11 Presenter: we could be trying to say, well, we’ll try and block it.

11:16 Presenter: That’s not a way forward.

11:18 Presenter: One other thing I want you to note is that because these platforms already have your

11:24 Presenter: business data, this means that these applications by definition are touching business data.

11:29 Presenter: Okay?

11:30 Presenter: So again, these are not applications that are used only for productivity.

11:36 Presenter: to facilitate real business processes.

11:40 Presenter: Now, you don’t actually need to take my word for it.

11:45 Presenter: Here are predictions by Gartner,

11:48 Presenter: and there’s also a quote from Satya here, Microsoft CEO.

11:53 Presenter: So you can see in the quote by Gartner,

11:56 Presenter: there are two numbers they are expecting to see.

12:00 Presenter: One of them is that by 2025,

12:03 Presenter: 75, 70% of new applications developed in the business will be developed with low-code,

12:10 Presenter: no-code. That’s huge, right? That’s incredible. And the second quote talks about low-code,

12:17 Presenter: no-code developers or developers outside of RIT outnumbering professional developers

12:23 Presenter: four to one. Now, you might be thinking that these numbers are, I don’t know, maybe they’re

12:29 Presenter: outdoor, right? How many of you think that these predictions will actually be true by 2025?

12:39 Presenter: Okay, how, how, exceeded. How many think that this is actually too much, that we won’t get

12:47 Presenter: by 2025? Anyone? Okay, we’ll see in a moment, we’ll try and figure out in a moment where we are.

12:56 Presenter: Look at the third quote here by Satya Nander.

13:00 Presenter: I think it’s Microsoft is, of course, one of the biggest drivers of the citizen development motion.

13:06 Presenter: And you can see just why.

13:09 Presenter: This is their attempt to try and help all of us solve all of the challenges that we’re going to need to solve in a scalable way.

13:17 Presenter: In a way that doesn’t require us to increase our engineering effort by 10x.

13:20 Presenter: And so before I move to the next slide, one thing that I wanted to do, these are predictions.

13:27 Presenter: And so I really wanted to try and understand what’s going on right now.

13:31 Presenter: How many citizen developers are there right now?

13:34 Presenter: And so I started to go through Microsoft earnings reports and just kind of grabbed numbers from over the years.

13:44 Presenter: And when you do that, you see you can create a trend of the number of citizen developers

13:50 Presenter: that Microsoft is reporting to be building on top of their platform.

13:54 Presenter: And now, and I’ll show you this number in a moment, but before I’m going to show you this number,

13:59 Presenter: I wanted to have some sort of a benchmark.

14:04 Presenter: I mean, if I give you a number, is it high, is it low? Who knows?

14:08 Presenter: So here’s the benchmark.

14:09 Presenter: Microsoft says that today there are over 5 million dotnet developers.

14:16 Presenter: That’s the statistics that you can find on Microsoft’s website.

14:20 Presenter: How many citizen developers on the Microsoft platforms do you think there are today?

14:27 Presenter: Think about it for a while.

14:28 Presenter: Have a number in your hand.

14:32 Presenter: Here it is.

14:33 Presenter: So these are all numbers that I’ve taken.

14:36 Presenter: and you can see the sources there,

14:38 Presenter: and if you want the specifics, just send me a note.

14:41 Presenter: I’ll send you the link.

14:42 Presenter: You can see that last year,

14:46 Presenter: they reported seven million citizen developers

14:48 Presenter: using Power Platform, using their local and local platform.

14:53 Presenter: You can see the kind of very rudimentary regression

14:57 Presenter: that I’ve created here, which puts them at around eight today.

15:01 Presenter: This is incredible, right?

15:04 Presenter: And Microsoft is only a very small subset of the market.

15:08 Presenter: There are plenty of other successful vendors that have huge platforms already.

15:12 Presenter: And so for us to think that we can wait and we can, and we don’t need to target this right

15:21 Presenter: now because I know you’re there, you’re very busy, you have a lot of things to do.

15:25 Presenter: Security is always overwhelmed.

15:28 Presenter: This is already happening.

The SDLC in Low‑Code Environments

15:30 Presenter: And where do you think these developers are walking?

15:35 Presenter: It’s us, it’s all of us, right?

15:37 Presenter: And so one important thing for us to try and understand is,

15:43 Presenter: how does it look like from a perspective of a single organization?

15:47 Presenter: So let’s say I’m a Fortune 500 company.

15:51 Presenter: I’m not sure if we’re using low code, no code, or we’re not.

15:55 Presenter: So let me show you an anonymous statistic from a single organization.

16:01 Presenter: This is a chart of the number of applications developed with low code, no code.

16:04 Presenter: in a single organization, right?

16:07 Presenter: These numbers are unprecedented.

16:10 Presenter: We’ve never had to deal with, how much is it,

16:13 Presenter: like 65K apps built in two years.

16:18 Presenter: I mean, now let’s think about

16:20 Presenter: what are the processes we can do behind it.

16:23 Presenter: I mean, can we do security reviews?

16:25 Presenter: Can we do threat modeling?

16:28 Presenter: I mean, can we just inventory those applications?

16:31 Presenter: No, we cannot.

16:34 Presenter: between 10x to 100x more applications

16:36 Presenter: that we’re used to dealing with.

16:38 Presenter: Now, of course, these are very small.

16:41 Presenter: Most of them are very small applications.

16:43 Presenter: And most of them are probably fine.

16:45 Presenter: Most of them are probably only

16:46 Presenter: by the person who’s created them.

16:49 Presenter: But do you know which ones?

16:51 Presenter: And do we know which ones

16:52 Presenter: have actually gone viral

16:54 Presenter: inside of our organization

16:56 Presenter: and are now being used by everyone

16:57 Presenter: or by everyone within the specific org?

17:00 Presenter: Inside of these 75k apps,

17:04 Presenter: the application developed by the marketing team and now everybody in the marketing team is using it.

17:09 Presenter: And what happens when that person leaves the organization and the app gets stale and people

17:14 Presenter: start asking questions of where this comes from? Or what happens if an auditor starts asking

17:20 Presenter: questions about how do we store the health data from the first application that we’ve seen?

17:24 Presenter: These applications are not part of the security umbrella. We are not there. We are not letting

17:30 Presenter: the business users make their own decisions.

17:32 Presenter: They are not equipped to make the right decisions.

17:36 Presenter: All right.

17:37 Presenter: Here’s a recap of this section.

17:39 Presenter: So first of all, this is a giant leap in productivity.

17:46 Presenter: And this is about enablement of your users.

17:49 Presenter: And we all know that the introduction of AI only makes this bigger.

17:54 Presenter: Because AI is being pushed into those local, local platforms

17:57 Presenter: to allow you to build applications even faster.

18:00 Presenter: even less technical capabilities.

18:04 Presenter: This is powering critical workflows.

18:07 Presenter: Not all of them are critical, but many of them are.

18:10 Presenter: And it is predicted to be the vast majority of applications

18:13 Presenter: that are built within our organizations.

18:15 Presenter: We can’t let this be something that happens

18:18 Presenter: without security being involved.

18:20 Presenter: This is probably happening in your own enterprise too.

18:23 Presenter: And you’ll find, by the way, not one platform.

18:25 Presenter: You’ll probably find, from what we are seeing,

18:28 Presenter: you’ll probably find between five and seven.

18:31 Presenter: There are millions of developers that are building with low-code, no-code today, that

18:37 Presenter: are part of the business.

18:38 Presenter: And in a large org, you’ll find tens of thousands of apps.

18:42 Presenter: Actually, the largest ones are closer to a million from what we’re seeing.

18:47 Presenter: Okay, so we’ve established that this is important.

18:50 Presenter: Now let’s try and figure out what can we do about it, or how does the process of building

18:56 Presenter: this application look like?

18:59 Presenter: Here’s the SDLC.

19:01 Presenter: This is kind of a very basic example.

19:05 Presenter: Of course, the SDLC varies between different organizations

19:08 Presenter: and different places, so this is not the important part.

19:13 Presenter: The important part is trying to figure out

19:14 Presenter: how does this relate to no code.

19:17 Presenter: But before we do that, one thing that is important for us

19:20 Presenter: to remember, that we are using the SDLC as a way to

19:27 Presenter: to set security controls.

19:30 Presenter: All of those security controls that you’re seeing right there,

19:32 Presenter: they are reliant on the fact that there is some sort of SDLC.

19:38 Presenter: Everything that is about the people that are building these applications,

19:41 Presenter: so security training, threat modeling, those things require a process.

19:47 Presenter: There are technical controls that we are putting in place,

19:50 Presenter: shift-left, code scanning, security gates.

19:53 Presenter: there is everything that’s about runtime.

19:56 Presenter: So monitoring, having the SOC,

19:59 Presenter: so the SOC would be able to actually

20:01 Presenter: do any sort of investigation there, right?

20:03 Presenter: Okay, now let’s compare this to no code.

20:06 Presenter: Here’s the worst case scenario for no code SDRC.

20:10 Presenter: You create something, and while you’re creating it,

20:13 Presenter: there’s an auto-save mechanism

20:15 Presenter: that actually pushes this to production, right?

20:17 Presenter: Now, it is important to know that in some cases,

20:22 Presenter: code applications can be built by professional development teams and then they probably do

20:27 Presenter: have some sort of a CICD pipeline, but the tools that they are provided are lacking.

20:34 Presenter: They are severely lacking.

20:36 Presenter: And so not only we are letting businesses that are building all of these applications,

20:42 Presenter: but none of our controls apply.

20:44 Presenter: And let’s try and figure this out together.

20:49 Presenter: But actually, one other thing I wanted to say here is that it’s important to note that

20:56 Presenter: this is why no code is successful. Because you don’t need to exchange like five different

21:02 Presenter: hands before the application gets developed. You have a problem, you fix the problem. This

21:06 Presenter: is great. This is innovation. This is helpful for organizations. But we can’t just leave

21:12 Presenter: without having security intertwined.

21:15 Presenter: We do need to find a new method to actually apply here.

21:19 Presenter: So here’s an attempt to try and think about

21:21 Presenter: all of the different security controls

21:24 Presenter: that we typically have with professional development

21:27 Presenter: and whether or not they apply to low code,

21:29 Presenter: or to low code, no code.

21:31 Presenter: So you’ll see that everything that relies

21:33 Presenter: on a human in the loop goes out the window

Security Gaps and Attack Surface Expansion

21:37 Presenter: because the scale just won’t let it happen.

21:40 Presenter: Even if you might be saying, okay, let’s just review the important apps.

21:44 Presenter: That’s fine.

21:45 Presenter: How do you find the important apps?

21:47 Presenter: That’s a challenge.

21:49 Presenter: There’s no code to scan, so code scanning won’t help you.

21:53 Presenter: There’s no CICD, so there’s no shift left.

21:56 Presenter: You’ll find that runtime monitoring would be very difficult.

22:00 Presenter: If something happens to one of these applications,

22:03 Presenter: your software will have nothing to do with it.

22:05 Presenter: They really won’t know how to find what’s going on there.

22:10 Presenter: What we’re seeing people do is a couple of things.

22:13 Presenter: One is some of these platforms will produce artifacts

22:15 Presenter: for you and then you can scan these artifacts.

22:18 Presenter: And the other is that if these platforms create a website,

22:24 Presenter: then you can do black box scanning of that website.

22:26 Presenter: Both of these produce a ton of false positives

22:29 Presenter: because they’re not aware of the actual,

22:32 Presenter: I mean how these things get built, right?

22:35 Presenter: They’re not aware of the platform,

22:36 Presenter: they’re not aware of the business logic behind it.

22:40 Presenter: it’s not a really viable solution.

22:44 Presenter: Okay, so as a recap on security controls,

22:50 Presenter: think about what is going on here.

22:51 Presenter: These are applications that have access

22:53 Presenter: to critical business data.

22:54 Presenter: They run on SaaS, which make them

22:56 Presenter: even more difficult to monitor.

22:59 Presenter: There’s lack in SDLC, lack in controls.

23:02 Presenter: Developers, business developers,

23:03 Presenter: have no security awareness for the things

23:05 Presenter: that they’re developing.

23:06 Presenter: And I’m not sure it’s even right

23:10 Presenter: I ask them that, right?

23:11 Presenter: They have their own thing to do.

23:12 Presenter: And the scale here is unprecedented.

23:16 Presenter: Okay, so most of the time we have left,

23:20 Presenter: I’m going to shift a perspective,

23:23 Presenter: because up until now, my perspective was

23:26 Presenter: from the enterprise perspective,

23:28 Presenter: from the blue team perspective.

23:29 Presenter: Now I’m going to shift to the other side,

23:31 Presenter: and I’ll show you how local local apps

23:36 Presenter: look for an attack, and how far,

23:40 Presenter: What can I gain out of it with an attacker’s perspective?

23:44 Presenter: Okay, so before I actually show you the first attack,

23:50 Presenter: I’m going to show you a quick video

23:52 Presenter: because I think it’s, maybe I’ll try to show you

23:56 Presenter: a quick video.

24:09 Presenter: Okay.

24:16 Presenter: Okay, and this is going to continue to play

24:19 Presenter: while I explain what’s going on.

24:22 Presenter: Basically, I’m going to solve a very specific use case.

24:27 Presenter: is using Slack as a way to communicate inside of the org.

24:31 Presenter: And one of the annoying features of Slack

24:33 Presenter: is that somebody can mention you on a public channel

24:36 Presenter: and then you’re expected to respond quickly,

24:39 Presenter: which might be annoying when you’re working on something else.

24:43 Presenter: And so what I’m doing here is I’m using Zapier

24:46 Presenter: to plug into Slack.

24:48 Presenter: And whenever somebody mentions me on a public channel,

24:50 Presenter: I’m going to change my status to appear as if I’m on a call.

24:54 Presenter: and so nobody will, I mean, they’ll be fine with me

24:59 Presenter: not replying and then five minutes later,

25:01 Presenter: I’m going to change back to an empty status

25:04 Presenter: so nobody will suspect that I do anything,

25:07 Presenter: that anything is wrong here.

25:09 Presenter: Now this is a very silly example, right?

25:12 Presenter: But notice how easy it is to create this,

25:16 Presenter: for me to create this application.

25:18 Presenter: This is a pretty sophisticated piece of software.

25:24 Presenter: to reach out to Slack APIs,

25:25 Presenter: it has to have some sort of an identity, right?

25:28 Presenter: Somehow it’s authenticated to Slack.

25:30 Presenter: It has, I mean, there’s a delay step here,

25:33 Presenter: so there’s five minutes where this thing is slipping.

25:36 Presenter: I mean, there’s some sort of a state.

25:38 Presenter: This is working kind of somewhere,

25:43 Presenter: it needs to be able to facilitate changes in the Slack API.

25:48 Presenter: It’s a big piece of software, right?

25:50 Presenter: I’m building it in two minutes,

25:54 Presenter: So this is just, this is how easy it is to create these applications.

25:58 Presenter: And we gotta give it to the platforms.

26:00 Presenter: They have done a great job at making it easier for people to build applications.

26:04 Presenter: This is great.

26:05 Presenter: One of the things that you’ll find in this demo, if you look closely,

26:09 Presenter: is that A, in nowhere here did I provide access to Slack.

26:14 Presenter: You didn’t see an OAuth pop up. We’ll talk about it in a moment.

26:17 Presenter: And the other thing that you’ll see is that when I’m finished with everything,

26:24 Presenter: to have a pop up, here it is, you see this little

26:28 Presenter: publish button, this is now in production.

26:31 Presenter: Right, this was the SDLC for you.

26:57 Presenter: Almost.

27:02 Presenter: Okay.

27:03 Presenter: So the first thing we want,

27:05 Presenter: the first thing we need to understand here

27:07 Presenter: is under which identity this is operating.

27:10 Presenter: How is Zapier connected to Slack?

27:13 Presenter: And when you look at it step by step,

27:17 Presenter: the first thing that you do,

27:19 Presenter: and by the way, this is not specific to Zapier,

27:22 Presenter: this is something with all of the different vendors.

27:24 Presenter: The first thing that you do with all of those platforms

27:26 Presenter: is that you choose which applications

27:28 Presenter: you’d like to connect to.

27:29 Presenter: The power of low-code, no-code is heavily reliant

27:32 Presenter: on the connectors that low-code, no-code has

27:34 Presenter: across your enterprises.

Credential Sharing as a Service: Mechanisms and Risks

27:36 Presenter: This is not something that stays within Office.

27:39 Presenter: This is something that plugs into different SAS vendors.

27:42 Presenter: It goes to on-prem, it goes to your cloud.

27:44 Presenter: And so these are these ready-made connectors

27:46 Presenter: that allow you to connect across your enterprise.

27:49 Presenter: So after you choose Slack,

27:50 Presenter: you get this kind of familiar overflow,

27:56 Presenter: which is requiring a bunch of permissions.

27:58 Presenter: Now, what permissions is this asking for?

28:03 Presenter: This is asking for all of the permissions

28:06 Presenter: that you might want to use when you’re using Slack.

28:10 Presenter: Not for the specific permissions

28:12 Presenter: that I’m going to use in this application, right?

28:15 Presenter: Once I go through this overflow,

28:17 Presenter: flow, I get something really cool that’s created.

28:21 Presenter: It’s an object called a connection.

28:23 Presenter: What is this connection?

28:25 Presenter: This connection has an amazing feature.

28:28 Presenter: It has a share button.

28:30 Presenter: What do you think I’m sharing here?

28:34 Presenter: This thing allows one user to share their own identity, their own connection to, for

28:39 Presenter: example, with another user.

28:42 Presenter: So let’s see, let’s try and figure out how this works.

28:45 Presenter: So on one side, there’s Zapier or Power Platform

28:49 Presenter: or any other local platform.

28:51 Presenter: And on the other side, there’s one enterprise,

28:56 Presenter: there’s an enterprise repository.

28:58 Presenter: It could be a SaaS service like Slack.

29:00 Presenter: It could be on-prem, whatever it is.

29:04 Presenter: How are they connected?

29:05 Presenter: So essentially what happens,

29:08 Presenter: and this is actually a slide from Microsoft Documentation,

29:11 Presenter: documentation is that there’s a storage there that is recording authentication tokens,

29:18 Presenter: OAuth refresh tokens, and allows users to share them with each other.

29:24 Presenter: So here’s the scenario.

29:25 Presenter: I build an application, and I want that application to have access to Slack, for example.

29:32 Presenter: I embed my own identity within that application using this refresh token, and now when I share

29:38 Presenter: this application with you, you’re actually using my identity.

29:42 Presenter: This is breaking the identity and access model of the enterprise.

29:48 Presenter: Because rather than having different users using their own identities, users can share

29:54 Presenter: identities of other users.

29:56 Presenter: And applications can run with the identities that belong to specific users.

30:04 Presenter: Now, because of this mechanism, what happens is that when you have lots of applications,

30:12 Presenter: and these are just examples I took off of marketplaces, where you see a bunch of applications

30:16 Presenter: that are being used by many people out of the marketplaces of the different platforms.

30:22 Presenter: What’s important to note about these applications is actually the logos, because behind each

30:30 Presenter: one of those logos is a connection.

30:32 Presenter: You need to connect to each one of those things.

30:36 Presenter: So these platforms are essentially

30:41 Presenter: becoming a giant bag of credentials

30:45 Presenter: that they are collecting whenever you build

30:48 Presenter: one of those applications.

30:50 Presenter: And so when you have lots of applications,

30:53 Presenter: you end up with lots of connections.

30:56 Presenter: And these are credentials.

31:00 Presenter: of credentials, it could be the users on credentials,

31:03 Presenter: it could be username and password to a SQL server.

31:07 Presenter: Those are several ways,

31:10 Presenter: several different kinds of connections.

31:12 Presenter: But because these platforms allow users

31:15 Presenter: to share these connections with each other,

31:18 Presenter: then essentially they are acting as

31:22 Presenter: what I like to call credential sharing as a service.

31:27 Presenter: Because when you can create these connections,

31:30 Presenter: can share them with everyone else.

31:31 Presenter: And one of the things that we’re actually finding

31:34 Presenter: is that in many of these platforms,

31:36 Presenter: there’s some notion of a default environment,

31:38 Presenter: one environment where all applications

31:40 Presenter: get created by default.

31:42 Presenter: And that share button can be shared with one specific user,

31:48 Presenter: but it could also be shared with the entire org.

31:51 Presenter: It can be shared with the entire default environment.

31:54 Presenter: And then what happens when you go to a large enterprise?

31:57 Presenter: You go to these default environments.

32:00 Presenter: find a bunch of credentials that are waiting for you.

32:02 Presenter: This is kind of preparing a privilege escalation for user.

32:06 Presenter: You can also think about it as a lateral movement

32:09 Presenter: because I can go from one user to another.

32:12 Presenter: I encourage you, if you’re a Microsoft shop, for example,

32:16 Presenter: go to the default environment in Microsoft Power Platform,

32:19 Presenter: which is part of Office, you’ll find SQL servers,

32:23 Presenter: you’ll find user connections to Teams,

32:25 Presenter: you’ll find user connections to Outlook.

32:27 Presenter: All of those things would just be available for you to use.

32:33 Presenter: One other thing that happens after people are leveraging these connections that have been shared or overshared with the entire organization,

32:41 Presenter: actually one point that’s important there is that when I say your entire organization, I mean everybody in your Azure AD instance, including guests.

32:52 Presenter: Okay, so when hackers are, when you get access to one of those connections, the next thing

32:57 Presenter: you can do is just use them to do whatever you want. And so here’s an example of ransomware

33:04 Presenter: written with no code. It’s pretty simple. So I’m just iterating, I’m just reaching out

33:11 Presenter: to a specific SharePoint site, I’m iterating over that SharePoint site. For each file,

33:16 Presenter: I’m encrypting the content of that file with an encryption function

33:20 Presenter: which is provided by the platform

33:22 Presenter: because there are valid use cases for an encryption function.

33:25 Presenter: And then I override the file.

33:27 Presenter: Now, this is for SharePoint, but you can imagine this for everywhere else

33:30 Presenter: because, again, these platforms can connect everywhere across your enterprise.

33:35 Presenter: Here’s one other example we’re seeing again and again.

33:38 Presenter: Data expetration.

33:41 Presenter: So the problem of having one of the things that people like to do in an enterprise is have the corporate email being routed to their own Gmail account.

33:52 Presenter: Because it’s just more convenient.

33:55 Presenter: So calendar events, for example.

33:57 Presenter: This is something that everybody wants to do.

33:59 Presenter: We have a bunch of tools that help us make sure that this doesn’t happen.

34:03 Presenter: There’s DLP.

34:04 Presenter: There’s things you can put on the email server.

34:06 Presenter: That’s great.

34:07 Presenter: Here’s what’s happening here.

Real‑World Attack Illustrations

34:09 Presenter: There’s a single application with one hand, with one connection, it connects to the corporate account.

34:15 Presenter: And with the other hand and another connection, it connects to the personal account.

34:20 Presenter: Instead of forwarding the email, they copy the content.

34:24 Presenter: How would you find this?

34:26 Presenter: This is not going through your network.

34:28 Presenter: This is running on the SaaS vendor’s own machine.

34:31 Presenter: The only way for you to know that this is happening is to go through each one of those applications

34:36 Presenter: that are being created on those platforms

34:40 Presenter: and find out which ones are doing it.

34:42 Presenter: And we are seeing this with email,

34:44 Presenter: we are seeing this with file shares,

34:46 Presenter: we are seeing this with many different,

34:49 Presenter: with everything you could expect.

34:52 Presenter: Because again, these applications, in many cases,

34:56 Presenter: don’t have an identity of their own.

35:00 Presenter: They use their user’s own identity.

35:03 Presenter: And so the user can, whatever the user can do,

35:06 Presenter: the user can now automate.

35:09 Presenter: One of the things that actually I forgot to mention earlier,

35:13 Presenter: but it’s important for us to know that this concept

35:17 Presenter: of allowing applications to run on behalf of users

35:20 Presenter: is also something that allows local platforms

35:24 Presenter: to actually provide their value.

35:25 Presenter: Because if business users would have to ask for permissions

35:29 Presenter: whenever they want to build something,

35:32 Presenter: we would never see this growth

35:34 Presenter: that we saw at the beginning of this talk.

35:36 Presenter: And so this is inherent in the way that these platforms work, because it’s inherent in the

35:44 Presenter: way that they enable business users to accomplish what they would like to do.

35:49 Presenter: Okay.

35:50 Presenter: Here’s something that might be a bit surprising.

35:52 Presenter: Yes?

35:56 Presenter: What you can do, what you can do is, I mean, there’s one positive note here.

36:07 Presenter: moving data outside of the corporate boundary,

36:10 Presenter: since forever, they’re just doing it with copy and paste.

36:15 Presenter: And with copy and paste, it’s difficult to find it.

36:19 Presenter: But right now, if they’re using a low-code,

36:21 Presenter: no-code platform, then you can ask someone.

36:24 Presenter: There’s an API for these platforms that would tell you,

36:28 Presenter: hey, show me all of the applications that were created

36:32 Presenter: on this platform.

36:33 Presenter: We never had this API for copy and paste files, right?

36:45 Presenter: The EDR unfortunately doesn’t have visibility here

36:49 Presenter: because this is not happening on somebody’s laptop,

36:51 Presenter: this is happening on the vendor’s SAS machine.

36:54 Presenter: And so, yeah.

36:56 Presenter: But one thing that the EDR is really important for

36:59 Presenter: and one area that might be a bit untrivial

37:03 Presenter: is that these platforms can also allow hackers

37:07 Presenter: to compromise machines.

37:11 Presenter: So there’s actually a component of low-code, no-code

37:13 Presenter: called RPA or a different version of low-code, no-code

37:16 Presenter: called RPA and many of the platforms now combine

37:19 Presenter: low-code, no-code and RPA itself.

37:22 Presenter: If you think about what RPA is doing,

37:25 Presenter: RPA is automation that runs on people’s laptops.

37:29 Presenter: impersonates the users, it runs on the user context,

37:32 Presenter: so it’s emulating the mouse and the keyboard.

37:35 Presenter: It’s running on the same context as the user.

37:39 Presenter: And it allows a cloud provider to send a command

37:44 Presenter: to somebody’s laptop, let that laptop do that command,

37:47 Presenter: and then get the results back.

37:50 Presenter: This is a C2 server that is plugging directly

37:54 Presenter: to users’ laptops, and what you’ll find in this link

37:59 Presenter: I gave a Defcon earlier this year,

38:01 Presenter: showing how the RPA vendor,

38:04 Presenter: the RPA agent that Microsoft has baked into Windows 11

38:10 Presenter: could easily be used by a hacker

38:12 Presenter: as a way to basically perform whatever you need to do

38:16 Presenter: with malware, just without writing malware.

38:19 Presenter: And this is all trusted, right?

38:21 Presenter: These are agents trusted by the ADR,

38:24 Presenter: all of the network addresses here belong to trusted vendors.

38:31 Presenter: One thing that I’m going to, one thing that I wanted to do

38:34 Presenter: is make sure that we give you some tools that would allow you

38:38 Presenter: to actually do something with this,

38:41 Presenter: allow you to kind of maybe play around with this

38:44 Presenter: and understand what is the amount,

38:47 Presenter: what, try and grasp how this problem,

38:50 Presenter: how big is this problem in your org.

38:52 Presenter: So one tool that you could use is upgrades.

38:57 Presenter: This is a very simple tool, right?

39:00 Presenter: You give it access to a specific user,

39:04 Presenter: and it will show you all of the connections

39:06 Presenter: that the user is actually able to use

39:08 Presenter: in a specific platform in Zapier.

39:11 Presenter: And it will also show you for which one of those connections

39:14 Presenter: who created that connection.

39:16 Presenter: So the ones to note, of course, are the connections

39:20 Presenter: that belong to another user.

39:23 Presenter: And we’re actually working on extending this tool

39:27 Presenter: So if you’re interested, just check it out.

39:29 Presenter: It’s open source for you to use.

39:31 Presenter: Okay.

39:35 Presenter: One other thing.

39:36 Presenter: Yes, please.

39:55 Presenter: So it depends on the way that you set up the application.

39:59 Presenter: You can build a low-code app in a way where every user logs in with their own identity

40:07 Presenter: using their own underlying connection to the data,

40:10 Presenter: to the actual data store.

40:11 Presenter: But you don’t have to.

40:13 Presenter: You can build an application in a way

40:15 Presenter: where all of the different users

40:18 Presenter: would use a single connection by a single user.

40:24 Presenter: Yes, exactly.

40:26 Presenter: Those connections, because as we said earlier,

40:28 Presenter: those connections get created with the maximum permissions

40:31 Presenter: that the platform can require.

Detection, Response, and Tooling

40:36 Presenter: Okay, one other thing that’s really important for us to understand is that now when everybody

40:43 Presenter: can create an application within our organization, applications of course can do whatever they

40:49 Presenter: want with the connection that you provide to them as a user.

40:51 Presenter: So here’s a nice idea.

40:54 Presenter: I will create an application that does something useful inside of an organization.

40:58 Presenter: Let’s say I have already compromised some users account within your org including a

41:04 Presenter: I will create a useful application, people will start using it.

41:07 Presenter: It will ask for users access to users’ emails.

41:12 Presenter: Because I don’t know, I will find out a good reason for it.

41:15 Presenter: While the user is using the application, I can do whatever I want with that connection.

41:19 Presenter: Right?

41:20 Presenter: So I’ll just take over their account.

41:23 Presenter: Now this is not a problem that’s new with low code.

41:27 Presenter: What’s new here is that business users can create this.

41:29 Presenter: That everybody can create this.

41:31 Presenter: And the other important point is that guess where this application will be hosted?

41:35 Presenter: It will be hosted on a trusted service, right?

41:39 Presenter: So let’s see that.

41:41 Presenter: Let’s see that in action.

41:50 Presenter: Almost.

41:56 Presenter: Okay.

41:57 Presenter: I’m specifically using Microsoft here.

42:01 Presenter: which is, I just took something off the marketplace.

42:04 Presenter: This is an application that is supposed to facilitate

42:07 Presenter: an out of office, so basically it will decline emails for you.

42:12 Presenter: Of course, an application that declines emails for you

42:14 Presenter: has to have access to your email.

42:17 Presenter: So I’m just showing you what this application is actually doing.

42:20 Presenter: What I’m going to do is create, is just add one, one-liner here.

42:26 Presenter: You can, you’ll see it in a moment.

42:27 Presenter: where while this application is actually operating,

42:31 Presenter: I’m gonna send an email on your behalf to my email

42:34 Presenter: saying I’ve been pwned.

42:35 Presenter: But of course I can do other things

42:38 Presenter: that are more disruptive.

42:40 Presenter: And while I’m writing this down,

42:44 Presenter: and it takes me some time to type,

42:47 Presenter: once I finish with this application,

42:50 Presenter: I’m gonna hit publish,

42:51 Presenter: and then I’m going to share it with everyone.

42:54 Presenter: And let me maybe,

42:56 Presenter: Let’s do, okay.

42:59 Presenter: So I’m done with the application.

43:01 Presenter: I’m going to publish the application.

43:03 Presenter: Again, no CICD, really quickly it’s in production.

43:08 Presenter: Now I get the ability to share this with people.

43:12 Presenter: I’m going to share it with everybody in my account,

43:14 Presenter: again, including guests, the entire AD tenant.

43:17 Presenter: And now this application exists on a specific URL.

43:20 Presenter: I get this URL which belongs to Microsoft.

43:22 Presenter: And with another user, I’m just going to go into that URL.

43:28 Presenter: I get this window asking me to share my connections.

43:33 Presenter: And once I say approve, the application runs.

43:38 Presenter: And of course, my email has been compromised.

43:51 Presenter: So what we’ve actually seen here is a way for people to create phishing campaigns within

43:57 Presenter: your organization with a link that provides, with a link that has one security mechanism.

44:05 Presenter: There’s one thing a user would need to do after they click this link inside of your

44:09 Presenter: organization.

44:14 Presenter: Here it is.

44:15 Presenter: This was the little kind of screen that we saw at the beginning when the user logged

44:23 Presenter: into this application.

44:24 Presenter: You notice that this is not the usual application, the usual asking for permissions that you

44:32 Presenter: see.

44:32 Presenter: This is not all of that.

44:33 Presenter: You’re not seeing the permissions that this is asking for.

44:35 Presenter: This is asking for an unbounded connection

44:39 Presenter: to these specific services.

44:40 Presenter: This is the only thing that’s stopping me

44:43 Presenter: from owning that account once the user has hit this link.

44:47 Presenter: And just think about it, this is a link

44:50 Presenter: they are going to see a lot.

44:51 Presenter: If you’re in an organization using Microsoft,

44:53 Presenter: they will have lots of these power-ups,

44:56 Presenter: everybody’s going to use them, they’re gonna trust them.

44:58 Presenter: Okay.

44:59 Presenter: The only thing that is actually,

45:01 Presenter: that might actually save us.

45:03 Presenter: However, you can turn this off.

45:07 Presenter: So there’s a feature that allows you to automatically provide consent here.

45:14 Presenter: And people are actually using this because it removes friction for people to use applications.

45:20 Presenter: If you’re an organization using Microsoft, I strongly recommend you to look at this specific flag and make sure it’s off.

45:28 Presenter: because if this flag is on, you have,

45:31 Presenter: the only thing I need to do in order to compromise the user,

45:34 Presenter: to establish phishing within your organization

45:37 Presenter: is to send somebody a link,

45:39 Presenter: and that link would be in the Microsoft domain.

45:43 Presenter: Okay.

45:46 Presenter: So we’ve seen,

45:49 Presenter: we’ve seen a bunch of attacks that are using,

45:53 Presenter: that are using the local platforms themselves.

45:57 Presenter: Thank you.

45:59 Presenter: I’m going to show you one more thing before I go to defense.

46:02 Presenter: And this is gonna be an interesting example.

46:06 Presenter: This is a slide from Microsoft Detection and Response Team

46:10 Presenter: where a few years ago, an APT group used a local platform

46:16 Presenter: as a way to remain persistent within the organization.

46:19 Presenter: Basically what happened is that they performed

46:21 Presenter: credential stuffing, they were able to compromise

46:24 Presenter: an admin account for a Microsoft tenant.

46:29 Presenter: And then rather than installing malware,

46:31 Presenter: moving laterally through the network,

46:33 Presenter: whatever we were expecting them to do,

46:35 Presenter: they created a single automation

46:38 Presenter: which used the e-discovery feature

46:40 Presenter: to search for secrets and PIR

46:42 Presenter: and then send it to an exfiltration endpoint.

46:45 Presenter: Right?

46:46 Presenter: This automation was up and running for six months

Strategic Recommendations and Closing

46:50 Presenter: while defenders were looking for it.

46:52 Presenter: They knew that they were compromised,

46:54 Presenter: threat actors in the network, but they couldn’t find it

46:57 Presenter: because who’s looking there?

46:59 Presenter: Nobody.

47:01 Presenter: So hackers are already taking advantage of it,

47:04 Presenter: and one thing that I’m going to show you,

47:07 Presenter: because I want us to have some time for questions,

47:09 Presenter: so one thing that I’m going to share

47:21 Presenter: is that basically if you want to try this out for yourself inside of your organization,

47:27 Presenter: you’ll find this is a tool that would help you.

47:31 Presenter: So essentially what we’ve done is we went through the attack that was performed by this APT group,

47:38 Presenter: we’ve reproduced it and we’ve packaged it into a tool

47:42 Presenter: that you can use in your own organization

47:44 Presenter: to check your own defenses.

47:46 Presenter: So try this out, you’ll be able to see whether or not

47:50 Presenter: you’ll be able to catch it or what types of logs

47:53 Presenter: you’ll have there.

47:55 Presenter: Okay, so one thing I do wanna make sure I leave you with

48:01 Presenter: before we finish off is how to,

48:06 Presenter: what is the best way forward?

48:08 Presenter: Okay, how do we do something really,

48:10 Presenter: what is the action item here?

48:12 Presenter: The first thing I’ll say is that,

48:16 Presenter: well, the first thing I’ll say is that

48:19 Presenter: there’s a bunch of information out there, right?

48:21 Presenter: You’re not alone, we are all in this together.

48:24 Presenter: There’s a very large community around this project.

48:28 Presenter: This is the OWASP Low-Code, No-Code, Top 10.

48:31 Presenter: This is all free to use.

48:32 Presenter: you’ll find many more examples than the ones

48:35 Presenter: that I shared here today.

48:37 Presenter: This is actually, we are hoping that you could use this

48:39 Presenter: as the basis for your low-code security standard.

48:45 Presenter: And this brings me to the opportunity that we have.

48:48 Presenter: Because there’s a huge opportunity

48:50 Presenter: all of us in this room have right now

48:53 Presenter: to create a security program for these types of applications.

48:57 Presenter: We need to understand how we can,

49:01 Presenter: how the security umbrella could apply to business development as well.

49:06 Presenter: There’s an opportunity to establish a local security standard

49:08 Presenter: and to create an inventory of these applications,

49:11 Presenter: understanding what applications are actually being built by your organization.

49:15 Presenter: There’s a bunch of tools you can leverage.

49:17 Presenter: There are a couple of tools we’ve seen already,

49:19 Presenter: and there’s also another tool that we haven’t, but you can find it on this link.

49:28 Presenter: I think that one of the things that’s important for us

49:31 Presenter: before we kind of finish off

49:35 Presenter: this might have been

49:38 Presenter: one of the things that was important for me in this talk

49:41 Presenter: is to give you enough ammunition

49:43 Presenter: enough examples

49:45 Presenter: so you can go and set it onward in your organization

49:49 Presenter: and get the right mindset

49:51 Presenter: for people to really address this problem

49:54 Presenter: However, I think that it’s important for us to understand that low-code, no-code can leave us in a better place than we were before.

50:03 Presenter: Because remember the point we made earlier.

50:07 Presenter: When low-code, no-code is replacing something, business users have been using, have been doing whatever they want since forever.

50:13 Presenter: They’ve just been using drag and drop.

50:15 Presenter: Now, when they’re using these platforms, if we partner with these platforms, if we look at what users are building these platforms, we can end up with better visibility, better controls than we ever had.

50:29 Presenter: Thank you very much. This has been great.

50:40 Presenter: We have time for questions, if there are any. Yes, please.

50:53 Presenter: So you’re absolutely right.

50:55 Presenter: And you’ll find that the OWASP top 10, in the OWASP top 10, only about two of the categories are focused on identity.

51:02 Presenter: You’ll find hard-coded secrets.

51:05 Presenter: You’ll find IDOs and other sort of classic application security vulnerabilities.

51:11 Presenter: And you’ll find plenty of examples in the top 10.

51:15 Presenter: I haven’t mentioned at all is supply chain.

51:18 Presenter: Low-code, no-code is only powerful because there are a bunch of widgets you can just

51:21 Presenter: pick up and use.

51:22 Presenter: The people who are building these widgets are not people that you trust by default,

51:30 Presenter: because they are not only the platform vendors themselves.

51:34 Presenter: Male Speaker 2

51:35 Presenter: Male Speaker 2

51:39 Presenter: Yes, it’s an app.

51:40 Presenter: I mean, it moves data, it does operations, it needs to log in.

51:46 Presenter: It’s just an app.

51:50 Presenter: For the school, you can have the most, just a normal user in the platform. You don’t

52:04 Presenter: have to, you don’t need to have any privilege access. Sure. Yes?

52:25 Presenter: The share button allows one user to share their connection with another user.

52:36 Presenter: Once you create a connection, you go through the OAuth consent flow.

52:40 Presenter: the platform will record your refresh token,

52:46 Presenter: and then will allow another user to use that refresh token.

52:49 Presenter: The user won’t get the actual access to the refresh token,

52:52 Presenter: but they will be able to send, to do operations,

52:56 Presenter: and behind the scenes, the platform will inject

52:58 Presenter: the refresh token by my user.

53:05 Presenter: There are lots of menus there.

53:07 Presenter: Some of the platforms are better than others

53:10 Presenter: in providing you with options, it’s important to know that most platforms would allow you

53:16 Presenter: to also use a service account. But most businesses don’t have access to service accounts, right?

53:21 Presenter: So that’s why this is being used.

53:25 Presenter: So for Azure, you know, or Power Apps, so you mentioned that there’s a way to remove,

53:33 Presenter: like you recommended turning off a flag, but that looks like it’s per app.

53:38 Presenter: So you actually have to, it’s not a global thing.

53:41 Presenter: So you actually have to list all the apps that have the permission set,

53:44 Presenter: and then disable that, and then kind of keep doing that

53:48 Presenter: to see if people are enabling apps with that permission, correct?

53:52 Presenter: You’re absolutely right.

53:53 Presenter: We need to own these applications.

53:55 Presenter: We need to be, in the same way that we are scanning code,

54:00 Presenter: that we are doing runtime monitoring for pro-code applications,

54:03 Presenter: we need to do the same for local apps.

54:06 Presenter: Okay, thanks.

54:10 Presenter: Thank you so much.

54:11 Presenter: I’ll still be here afterwards.

54:15 Presenter: Thank you for staying with me.