Web 2.0 users beware: Social networking technologies may be fun and useful, but the one thing they are not is secure. For all the benefits it offers, the Web 2.0 world is still pretty rowdy, and the risk to enterprises is very serious. Experts warn that capabilities such as social networking and collaborative content sites are a wide-open window to hackers who are using their mega-networking appeal to spread malware and crack into systems. Unless organizations take precautions, not only do they put themselves at risk, but they also may inadvertently become members of a ring of thieves whose goal is to get their virtual hands on information, which equals riches.
Information systems security companies see a whole new world of business opportunities opening up to them with the ever-widening use of Web 2.0 offerings. A study conducted by Forrester Research Incorporated, Cambridge, Massachusetts, reveals that Web 2.0 technologies are already in use or prevalent within organizations but with little regard for the security implications. Commissioned by Secure Computing Corporation, Ocala, Florida, the survey showed that while 96 percent of respondents reported finding value from the use of Web 2.0 applications, only 5 percent actually implemented comprehensive protection mechanisms.
Paul A. Henry, vice president of technology evangelism, Secure Computing, finds it appalling that 97 percent of organizations are still using packet filters as their firewalls when the threat vector switched five years ago to the application layer. “So essentially everybody is out there today living in the Web 2.0 world using Web 1.0 risk mitigation,” Henry states. “Seventy percent of these people are reporting breaches and they wonder why. It escapes me completely.”
The bi-directional interaction that is the essence of Web 2.0 makes it a prime venue for hackers. Web sites such as Wikipedia thrive on people adding content; however, organizations that…