Sep 18 2007
AJAX Security Quote of the Day
Security: don’t even get me started on the security challenges in an environment full of widgets, gadgets and 3rd party web services. Suffice it to say that when this rock gets turned over, lots of ugly stuff creepy-crawly things will slither out.- Chris Keene blogging on the state of AJAX in general and on his company’s acquisition of TurboAjax
uh.. yeah. What he said! I am doing lots of AJAX in the stuff I am developing, and being a security guy in many of my ‘past lives’ I am bullet-proofing everything on the server side (not much you can do to protect the client side. Sorry; it’s the price we pay for “cool,” or as my dear friend Chuck Yerkes might have said: “Secure, powerful, pretty: Choose two.”) On the larger front about the AJAX universe needing a “RedHat”-like consolidation…. it might be premature for that to happen just now - there’s too much interesting framework-level stuff still being developed, but it’s going to happen eventually… AJAX just like every popular technology platform will hit a standardization-level critical mass where in order to be widely used (read: used in “enterprise markets”) it will have to have the same level of managerial trust that Java and other now-mainstream development tools do.
On the bright side, at least we have advanced to the point where its possible to bring new ideas into the mainstream of IT, and people with attitudes like this:
“Within an EDP Center, programming languages should be standardized. If it’s COBOL, PL-1, or FORTRAN, so be it. And the bright young mavericks with their ALGOL, PASCAL and god-knows-what-else will just have to conform.”
- John M. Carroll in Computer Security Magazine, 1977
have, hopefully, long ago gone off to their reward in some dreary retirement home.
Leave a Reply
You must be logged in to post a comment.










Posts