Web 2.0 Security

If you start a conversation today and ask “what are you working on?” the answers you get are interesting - “web 2.0″, “SOA”, “Web Services”.  If you ask followup questions on this, you will get more confused about what is this is all about.  So, what is the problem here?  Well, terminology has been overloaded and technologists are trying to put meaning into marketing terms. 

Based on customer surveys related to Web 2.0 technologies and security, I found a common theme.  It is this theme that has been documented in my white paper on Web 2.0 Security.  Feel free to chime in on your thoughts …

2 Responses to “Web 2.0 Security”

  1. Ravi Char Says:

    Shivaram:

    Congrats on your blog.

    Web 2.0 is a term often misunderstood and it has multiple interpretations. I commend you for addressing security issue in this area.

    Information Security is all about protecting data - Confidentiality-Integrity- Availability. This objective of protecting data does not change with technology used to access the data. The goal is to deploy technology to access the data at the same time preserve the objective of protecting the data. In your Whitepaper you are right on, when you say usage determines the threat scenarios this is where Web 2.0 differs significantly from earlier web - I look forward to read your thoughts on this.

  2. Shivaram Mysore Says:

    This white paper is also posted on Help Net Security: http://www.net-security.org/article.php?id=1108

Leave a Reply