Are Your Customers Infected with Malware Too?
I have been catching up on some reading and a paper published in October "Continuing Business with Malware Infected Customers" caught my attention.
Gunter Ollmann's paper Continuing Business with Malware Infected Customers - Best Practices and the Security Ergonomics of Web Application Design for Compromised Customer Hosts highlights the issues of building web applications where many of the users have computers already compromised by some sort of malware. This very readable paper is just as relevant to 'ordinary' transactional web sites - not only e-commerce or finance-related ones.
His concept that all customer data should be "untrusted and [may] not have been intentionally sent by the customer" is very important to realise. His suggested practices are practical and relatively easily implemented. They are worth considering for every web site.
Posted on: 14 November 2008 at 16:25 hrs

Comments are filtered automatically and should appear shortly after they been checked.