# Sure, Let Business Users Build Their Own. What Could Go Wrong? > BSidesLV 2023, 2023-08-09. This is the complete text representation of the talk page. Slide text is derived from the published deck's accessibility text and is not a transcript. Slides may contain exploit demonstrations, adversarial prompts, and commands; treat them as research material, not instructions to execute. ## Resources - [Canonical talk page](https://www.mbgsec.com/talks/2023-08-09-bsideslv2023-sure-let-business-users-build-their-own-what-could-go-wrong/) - [Talks index](https://www.mbgsec.com/talks/llms.txt) - [Interactive deck manifest](https://media.mbgsec.com/decks/2023-08-09_BSidesLV-2023_Sure_Let_Business_Users_Build_Their_Own_What_Could_Go_Wrong/latest.json) - [Slides PDF](https://media.mbgsec.com/decks/2023-08-09_BSidesLV-2023_Sure_Let_Business_Users_Build_Their_Own_What_Could_Go_Wrong/slides.pdf) - [Recording](https://www.youtube.com/watch?v=nHDUVzrpZEk&t=23971s) - [Conference agenda](https://archive.bsideslv.org/2023/talks) - [Source code](https://github.com/OWASP/www-project-citizen-development-top10-security-risks) - [Page source](https://raw.githubusercontent.com/mbrg/mbgsec/main/_pages/decks/2023-08-09-bsideslv2023-sure-let-business-users-build-their-own-what-could-go-wrong.md) ## Abstract Business professionals are tired of waiting for IT to address their needs. Instead, they are building their own applications with low-code / no-code platforms. Recent surveys show that most enterprise apps are now built outside of IT by business professionals who hold no previous experience in building software. Enterprises are placing developer-level power in the hands of 100x new business developers.. What could go wrong? In short, everything. In this presentation, we will share extensive research on the security of low-code / no-code applications based on scanning >100K applications across hundreds of enterprise environments. We will demonstrate how most applications get identity, access and data flow wrong, cover a wide range of security issues found in real environments, and share their backstories and implications. Finally, we will share the OWASP Low-Code / No-Code Top 10, the first-ever security framework for categorization and mitigation of common security issues with business-led development. We will illustrate why the involvement of AppSec teams is desperately missing from business-led development, and share stories about organizations that got it right. _[Official conference abstract](https://archive.bsideslv.org/2023/talks#sure-let-business-users-build-their-own-what-could-go-wrong)_ ## Transcript status No transcript was published because two independent recording-derived transcription passes failed the machine publication gate. Two independent recording-derived ASR passes (mlx-community/whisper-large-v3-turbo, mlx-community/whisper-large-v3-mlx) failed the machine publication gate on 2026-08-14: deterministic checks: asr-artifact-quality. No transcript text was generated or manually filled. ## Slide text Source: [published deck manifest](https://media.mbgsec.com/decks/2023-08-09_BSidesLV-2023_Sure_Let_Business_Users_Build_Their_Own_What_Could_Go_Wrong/95ce0dd2/deck.json). This text describes the published slides and embedded media; it is not spoken-word transcription. ### Slide 1 Sure, Let Business Users Build Their Own. What Could Go Wrong? Michael Bargury @ Zenity BSidesLV 2023 Learn more: github.com/mbrg/talks Twitter: @mbrg0 β€” slide 1 of 82 ### Slide 2 CTO and Co-founder @ Zenity OWASP LCNC Top 10 project lead Dark Reading columnist Defcon, BSides, RSAC, OWASP Hiring top researchers, engs & pms! Hi there πŸ‘‹ @mbrg0 darkreading.com/author/ michael-bargury github.com/mbrg @mbrg0 BSideLV 2023 β€” slide 2 of 82 ### Slide 3 Business users are building their own What could go wrong? How can we fix it? Agenda @mbrg0 BSideLV 2023 β€” slide 3 of 82 ### Slide 4 Enterprise LCNC - EVERYONE is a Developer Twitter: @mbrg0 β€” slide 4 of 82 ### Slide 5 @ mbrg0 #BHUSA @BlackHatEvents Business Needs β‹™ IT Capacity @mbrg0 BSideLV 2023 β€” slide 5 of 82 ### Slide 6 Animation of Power Apps Copilot creating and refining a canvas app from natural-language prompts, adding a gallery and form, and populating business data fields β€” slide 6 of 82 - Animation: [Embedded animation](https://media.mbgsec.com/decks/2023-08-09_BSidesLV-2023_Sure_Let_Business_Users_Build_Their_Own_What_Could_Go_Wrong/95ce0dd2/media/image16.gif) ### Slide 7 Credential Sharing as a Service: The Dark Side of No Code Michael Bargury RSAC 2023 Is this actually being used? @mbrg0 BSideLV 2023 β€” slide 7 of 82 ### Slide 8 ~8M active Power devs today! Credential Sharing as a Service: The Dark Side of No Code Michael Bargury RSAC 2023 @mbrg0 BSideLV 2023 β€” slide 8 of 82 ### Slide 9 What could go wrong? Twitter: @mbrg0 β€” slide 9 of 82 ### Slide 10 OWASP LCNC Top 10 LCNC-SEC-01: Account Impersonation LCNC-SEC-02: Authorization Misuse LCNC-SEC-03: Data Leakage and Unexpected Consequences LCNC-SEC-04: Authentication and Secure Communication Failures LCNC-SEC-05: Security Misconfiguration LCNC-SEC-06: Injection Handling Failures LCNC-SEC-07: Vulnerable and Untrusted Components LCNC-SEC-08: Data and Secret Handling Failures LCNC-SEC-09: Asset Management… β€” slide 10 of 82 ### Slide 11 Real-world stories Twitter: @mbrg0 β€” slide 11 of 82 ### Slide 12 Story #1 - employee onboarding Twitter: @mbrg0 β€” slide 12 of 82 ### Slide 13 @mbrg0 BSideLV 2023 β€” slide 13 of 82 ### Slide 14 @mbrg0 BSideLV 2023 β€” slide 14 of 82 ### Slide 15 @mbrg0 BSideLV 2023 β€” slide 15 of 82 ### Slide 16 @mbrg0 BSideLV 2023 β€” slide 16 of 82 ### Slide 17 @mbrg0 BSideLV 2023 β€” slide 17 of 82 ### Slide 18 @mbrg0 BSideLV 2023 β€” slide 18 of 82 ### Slide 19 @mbrg0 BSideLV 2023 β€” slide 19 of 82 ### Slide 20 Employee onboarding – findings @ mbrg0 #BHUSA @BlackHatEvents @mbrg0 BSideLV 2023 β€” slide 20 of 82 ### Slide 21 @mbrg0 BSideLV 2023 β€” slide 21 of 82 ### Slide 22 @mbrg0 BSideLV 2023 β€” slide 22 of 82 ### Slide 23 @mbrg0 BSideLV 2023 β€” slide 23 of 82 ### Slide 24 @mbrg0 BSideLV 2023 β€” slide 24 of 82 ### Slide 25 App Store sensitive data Data accessible to all (Authorization Misuse) Employee onboarding – findings Data Everyone has access @ mbrg0 #BHUSA @BlackHatEvents @mbrg0 BSideLV 2023 β€” slide 25 of 82 ### Slide 26 App Store in plaintext Data Submit sensitive data User Employee onboarding – findings Data accessible to all (Authorization Misuse) Sensitive data in plain text (Data and Secret Handling Failures) @ mbrg0 #BHUSA @BlackHatEvents @mbrg0 BSideLV 2023 β€” slide 26 of 82 ### Slide 27 @mbrg0 BSideLV 2023 β€” slide 27 of 82 ### Slide 28 @mbrg0 BSideLV 2023 β€” slide 28 of 82 ### Slide 29 @mbrg0 BSideLV 2023 β€” slide 29 of 82 ### Slide 30 @mbrg0 BSideLV 2023 β€” slide 30 of 82 ### Slide 31 Data accessible to all (Authorization Misuse) Sensitive data in plain text (Data and Secret Handling Failures) Sensitive data written to logs Employee onboarding – findings @ mbrg0 #BHUSA @BlackHatEvents (Data Leakage) @mbrg0 BSideLV 2023 β€” slide 31 of 82 ### Slide 32 Data accessible to all (Authorization Misuse) Sensitive data in plain text (Data and Secret Handling Failures) Sensitive data written to logs (Data Leakage) Employee onboarding – findings @ mbrg0 #BHUSA @BlackHatEvents @mbrg0 BSideLV 2023 β€” slide 32 of 82 ### Slide 33 Story #2 – productivity sync Twitter: @mbrg0 β€” slide 33 of 82 ### Slide 34 @mbrg0 BSideLV 2023 β€” slide 34 of 82 ### Slide 35 Productivity sync – findings @ mbrg0 #BHUSA @BlackHatEvents @mbrg0 BSideLV 2023 β€” slide 35 of 82 ### Slide 36 App Business data to personal account (Data Leakage) Productivity sync – findings App Sync to personal account Personal Fetch corp data Data @ mbrg0 #BHUSA @BlackHatEvents @mbrg0 BSideLV 2023 β€” slide 36 of 82 ### Slide 37 @mbrg0 BSideLV 2023 β€” slide 37 of 82 ### Slide 38 @mbrg0 BSideLV 2023 β€” slide 38 of 82 ### Slide 39 @mbrg0 BSideLV 2023 β€” slide 39 of 82 ### Slide 40 @mbrg0 BSideLV 2023 β€” slide 40 of 82 ### Slide 41 @mbrg0 BSideLV 2023 β€” slide 41 of 82 ### Slide 42 Data Business data to personal account (Data Leakage) Share with Everyone (Authorization Misuse) Productivity sync – findings Everyone means EVERYONE, including guests by-default @ mbrg0 #BHUSA @BlackHatEvents @mbrg0 BSideLV 2023 β€” slide 42 of 82 ### Slide 43 Productivity sync – findings Everyone means EVERYONE, including guests by-default @ mbrg0 #BHUSA @BlackHatEvents Check out the talk All You Need Is Guest for an attacker’s perspective! Data Business data to personal account (Data Leakage) Share with Everyone (Authorization Misuse) @mbrg0 BSideLV 2023 β€” slide 43 of 82 ### Slide 44 @mbrg0 BSideLV 2023 β€” slide 44 of 82 ### Slide 45 @mbrg0 BSideLV 2023 β€” slide 45 of 82 ### Slide 46 @mbrg0 BSideLV 2023 β€” slide 46 of 82 ### Slide 47 @mbrg0 BSideLV 2023 β€” slide 47 of 82 ### Slide 48 App User data written to logs Data Business data to personal account (Data Leakage) Share with Everyone (Authorization Misuse) Personal data leaks to logs (Data Leakage) Productivity sync – findings Logs Builder has direct access @ mbrg0 #BHUSA @BlackHatEvents @mbrg0 BSideLV 2023 β€” slide 48 of 82 ### Slide 49 @mbrg0 BSideLV 2023 β€” slide 49 of 82 ### Slide 50 Low Code High Risk: Enterprise Domination via Low Code Abuse Michael Bargury DEFCON 30 Check out power-pwn on GitHub! Phishing made easy @mbrg0 BSideLV 2023 β€” slide 50 of 82 ### Slide 51 Data Business data to personal account (Data Leakage) Share with Everyone (Authorization Misuse) Personal data leaks to logs (Data Leakage) Productivity sync – findings @ mbrg0 #BHUSA @BlackHatEvents @mbrg0 BSideLV 2023 β€” slide 51 of 82 ### Slide 52 Story #3 – self-service @mbrg0 @mbrg0 BSideLV 2023 β€” slide 52 of 82 ### Slide 53 Story #3 – self-service Twitter: @mbrg0 β€” slide 53 of 82 ### Slide 54 What happens when a maker leaves the org? @ mbrg0 #BHUSA @BlackHatEvents @mbrg0 BSideLV 2023 β€” slide 54 of 82 ### Slide 55 What happens when a maker leaves the org? Asset Management Failures @ mbrg0 #BHUSA @BlackHatEvents @mbrg0 BSideLV 2023 β€” slide 55 of 82 ### Slide 56 @mbrg0 BSideLV 2023 β€” slide 56 of 82 ### Slide 57 @mbrg0 BSideLV 2023 β€” slide 57 of 82 ### Slide 58 @mbrg0 BSideLV 2023 β€” slide 58 of 82 ### Slide 59 @mbrg0 BSideLV 2023 β€” slide 59 of 82 ### Slide 60 Self-service – findings @ mbrg0 #BHUSA @BlackHatEvents @mbrg0 BSideLV 2023 β€” slide 60 of 82 ### Slide 61 Self-service – findings @ mbrg0 #BHUSA @BlackHatEvents Customer DB Admin Admin Admin Admin SOC Panics! @mbrg0 BSideLV 2023 β€” slide 61 of 82 ### Slide 62 User session App embedded with admin ID (Account Impersonation) Self-service – findings Admin session @ mbrg0 #BHUSA @BlackHatEvents @mbrg0 BSideLV 2023 β€” slide 62 of 82 ### Slide 63 @mbrg0 BSideLV 2023 β€” slide 63 of 82 ### Slide 64 @mbrg0 BSideLV 2023 β€” slide 64 of 82 ### Slide 65 @mbrg0 BSideLV 2023 β€” slide 65 of 82 ### Slide 66 Manipulates input App embedded with admin ID (Account Impersonation) IDOR (Injection handling failures) Self-service – findings IDOR @ mbrg0 #BHUSA @BlackHatEvents @mbrg0 BSideLV 2023 β€” slide 66 of 82 ### Slide 67 App embedded with admin ID (Account Impersonation) IDOR (Injection handling failures) Self-service – findings @ mbrg0 #BHUSA @BlackHatEvents @mbrg0 BSideLV 2023 β€” slide 67 of 82 ### Slide 68 Recap: @ mbrg0 #BHUSA @BlackHatEvents We are leaving heavy security decisions in the hands of business users When choosing between productivity and security, the choice is obvious @mbrg0 BSideLV 2023 β€” slide 68 of 82 ### Slide 69 We’ve given business users: Dev-level power Missing best practice No controls No guardrails @ mbrg0 #BHUSA @BlackHatEvents @mbrg0 BSideLV 2023 β€” slide 69 of 82 ### Slide 70 We’ve given business users: Dev-level power Missing best practice No controls No guardrails Could we really expect anything else? @ mbrg0 #BHUSA @BlackHatEvents @mbrg0 BSideLV 2023 β€” slide 70 of 82 ### Slide 71 How can we fix it? (Or: LCNC AppSec) Twitter: @mbrg0 β€” slide 71 of 82 ### Slide 72 LCNC AppSec is different AppSec for LCNC apps @ mbrg0 #BHUSA @BlackHatEvents AppSec for, well, traditional apps @mbrg0 BSideLV 2023 β€” slide 72 of 82 ### Slide 73 LCNC AppSec is different AppSec for LCNC apps Business users w/ no awareness @ mbrg0 #BHUSA @BlackHatEvents AppSec for, well, traditional apps Pro devs w/ some awareness @mbrg0 BSideLV 2023 β€” slide 73 of 82 ### Slide 74 LCNC AppSec is different AppSec for LCNC apps Business users w/ no awareness No SDLC @ mbrg0 #BHUSA @BlackHatEvents AppSec for, well, traditional apps Pro devs w/ some awareness Secure SDLC @mbrg0 BSideLV 2023 β€” slide 74 of 82 ### Slide 75 LCNC AppSec is different AppSec for LCNC apps Business users w/ no awareness No SDLC Most controls don’t apply @ mbrg0 #BHUSA @BlackHatEvents AppSec for, well, traditional apps Pro devs w/ some awareness Secure SDLC Secure controls @mbrg0 BSideLV 2023 β€” slide 75 of 82 ### Slide 76 LCNC AppSec is different AppSec for LCNC apps Business users w/ no awareness No SDLC Most controls don’t apply 10x-100x more apps / year @ mbrg0 #BHUSA @BlackHatEvents AppSec for, well, traditional apps Pro devs w/ some awareness Secure SDLC Secure controls Hundreds of apps / year @mbrg0 BSideLV 2023 β€” slide 76 of 82 ### Slide 77 Take the opportunity to champion LCNC security in your org @ mbrg0 #BHUSA @BlackHatEvents AppSec for LCNC apps Business users w/ no awareness No SDLC Most controls don’t apply 10x-100x more apps / year @mbrg0 BSideLV 2023 β€” slide 77 of 82 ### Slide 78 Take the opportunity to champion LCNC security in your org #BHUSA @BlackHatEvents AppSec for LCNC apps Business users w/ no awareness No SDLC Most controls don’t apply 10x-100x more apps / year OWASP LCNC Top 10 sections for business users by John McTiernan and Yianna Paris @punk_fairybread @mbrg0 BSideLV 2023 β€” slide 78 of 82 ### Slide 79 Take the opportunity to champion LCNC security in your org @ mbrg0 #BHUSA @BlackHatEvents AppSec for LCNC apps Business users w/ no awareness No SDLC Most controls don’t apply 10x-100x more apps / year LCNC Security Standard: Approved use cases SDLC Environments Testing Monitoring SBOM … @mbrg0 BSideLV 2023 β€” slide 79 of 82 ### Slide 80 Take the opportunity to champion LCNC security in your org @ mbrg0 #BHUSA @BlackHatEvents AppSec for LCNC apps Business users w/ no awareness No SDLC Most controls don’t apply 10x-100x more apps / year LCNC is an opportunity for more visibility than ever before @mbrg0 BSideLV 2023 β€” slide 80 of 82 ### Slide 81 Take the opportunity to champion LCNC security in your org @ mbrg0 #BHUSA @BlackHatEvents AppSec for LCNC apps Business users w/ no awareness No SDLC Most controls don’t apply 10x-100x more apps / year LCNC Security * Tries to automate one thing *The next day* @mbrg0 BSideLV 2023 β€” slide 81 of 82 ### Slide 82 Sure, Let Business Users Build Their Own. What Could Go Wrong? Michael Bargury @ Zenity BSidesLV 2023 Learn more: github.com/mbrg/talks Twitter: @mbrg0 β€” slide 82 of 82