Sep 18 2007

AJAX Security Quote of the Day

Published by David HM Spector at 10:42 pm under AJAX, Web2.0

Security: don’t even get me started on the security challenges in an environment full of widgets, gadgets and 3rd party web services. Suffice it to say that when this rock gets turned over, lots of ugly stuff creepy-crawly things will slither out.- Chris Keene blogging on the state of AJAX in general and on his company’s acquisition of TurboAjax

uh.. yeah. What he said! I am doing lots of AJAX in the stuff I am developing, and being a security guy in many of my ‘past lives’ I am bullet-proofing everything on the server side (not much you can do to protect the client side. Sorry; it’s the price we pay for “cool,” or as my dear friend Chuck Yerkes might have said: “Secure, powerful, pretty: Choose two.”) On the larger front about the AJAX universe needing a “RedHat”-like consolidation…. it might be premature for that to happen just now - there’s too much interesting framework-level stuff still being developed, but it’s going to happen eventually… AJAX just like every popular technology platform will hit a standardization-level critical mass where in order to be widely used (read: used in “enterprise markets”) it will have to have the same level of managerial trust that Java and other now-mainstream development tools do.

On the bright side, at least we have advanced to the point where its possible to bring new ideas into the mainstream of IT, and people with attitudes like this:

“Within an EDP Center, programming languages should be standardized. If it’s COBOL, PL-1, or FORTRAN, so be it. And the bright young mavericks with their ALGOL, PASCAL and god-knows-what-else will just have to conform.”

- John M. Carroll in Computer Security Magazine, 1977

have, hopefully, long ago gone off to their reward in some dreary retirement home.

Trackback URI | Comments RSS

Leave a Reply

You must be logged in to post a comment.