Web 2.0 Security

1 - I can do better 2 - Jury's out 3 - Pretty darn good 4 - Splendiferous 5 - Awesometastic by 0 people | Log in to rate

Ranked #41,793 in Tech & Geek, #753,873 overall

Web 2.0 is all about sharing right? Well as we poor more and more of our private and business life into Web 2.0 applications security gets more and more important.

In this lens I will explore various approaches to security in Web 2.0. Hopefully I will be able to figure out what us the users should demand from our web applications as well as what service providers like myself should be doing.

Foundation reading on security for Web applications 

Trust points and Breach points in Web Apps
My own introduction to security for web 2.0 applications. Introduces you to the concept of you (the service operator) being a security risk for your clients.
Top 10 Web Application Security Vulnerabilities
This list gets updated regularly by OWASP (Read their whole site).
Schneier on Security: Weakest Link Security
Funny little story about physical security which provides a lesson for web 2.0 apps as well.

Security conscious Web 2.0 sites 

WideWord
This is my own encrypted document writing and sharing site.
E-Gold
These guys were doing secure web 2.0 before just about anyone else. It's a gold backed electronic currency with a huge infrastructure of independent web services on top of it.
HushMail
Secure and encrypted web email.
Loom
A very interesting approach to payments Web 2.0 style.
Strongspace.com
This is a security conscious file storage site. All connections with the server as well as some of your data such as passwords are encrypted. Bear in mind though that any files that you place on the server are not encrypted, kudos to Strongspace for specifying this upfront.

Financial Cryptography 

While really about crypto for use in financial applications Ian's writings are particularly applicable to Web 2.0 applications. When will we first see phishing attacks on Basecamp?

Loading Fetching RSS feed... please stand by

Usable Security 

Loading Fetching RSS feed... please stand by

Related books 

Translucent Databases

This book is a practical guide to use encryption within your database. It is vital to design this in from the beginning.

Amazon Price: $29.95 (as of 07/13/2009) Buy Now

Secrets and Lies: Digital Security in a Networked World

What is security? This is not a technical book, but should really be read by anyone who is in the business of web 2.0.

Amazon Price: $12.21 (as of 07/13/2009) Buy Now

Security and Usability: Designing Secure Systems that People Can Use

This new book looks very promissing. Usability is one of the most important aspects of Web 2.0 security.

Amazon Price: $38.17 (as of 07/13/2009) Buy Now

by pelle

My main interests are web technology, crypto, Ruby on Rails, startups, economics, libertarianism, travel, food, drink and music.

I run a couple of bl...

(more)

Favorited By

Create a Lens!