Andreas Engel - BizDev & Marketing Consulting
Because I can do!
andreasengel.com
Saturday, June 28, 2008
  Setting a New Web-Standard with OAuth for Secure API Authentication
Current trends in information architecture, the development of user-provided information and the use and combination of single function focused applications show that the Internet is shifting to a medium that is more and more structured with a decentralized authority.
Instead of using a single site for all online needs users use different sites and services to manage their online experience applying state of the art Data APIs allowing aplications to access their data. Making use of a Web-standard like OAuth for secure API authentication gives your users access to their data while protecting their passwords and other protected areas. From OAuth:
"Many luxury cars today come with a valet key. It is a special key you give the parking attendant and unlike your regular key, will not allow the car to drive more than a mile or two. Some valet keys will not open the trunk, while others will block access to your onboard cell phone address book. Regardless of what restrictions the valet key imposes, the idea is very clever. You give someone limited access to your car with a special key, while using your regular key to unlock everything."
Here is a short demo of what it means to end users:

While reviewing one of the latest Google innovations, Google App Engine, which lets one run Web applications on Google's infrastructure with no servers to maintain I found it worth to mention OAuth as an open standard for secure API authentication - OAuth is now supported on all of the Google Data APIs. Being familiar with UML or sequence diagrams it's easy to understand the Google data API authentication process. More on Google Data APIs blog.


Resources:

Labels: , , , , , , , ,

 
Thursday, February 14, 2008
  Handling Open Web Application Security
As the market dynamics change digital business is quickly becoming the method of choice for any enterprise to offer products and services on-demand to their market applying next-generation information infrastructures with AJAX as an ideal partner to complement modern SOA architectures.

But moving applications to the Web also brings up a lot of questions how to deal with security issues. The OWASP is an open project and a community to help make informed decisions about Web application security risks. In 2007 the most serious web application vulnerabilities (as PDF) were:
  1. Cross Site Scripting (XSS)
  2. Injection Flaws
  3. Malicious File Execution
  4. Insecure Direct Object Reference
  5. Cross Site Request Forgery (CSRF)
  6. Information Leakage and Improper Error Handling
  7. Broken Authentication and Session Management
  8. Insecure Cryptographic Storage
  9. Insecure Communications
  10. Failure to Restrict URL Access
For the most prevalent Web application frameworks and especially for open source development, where open source software became the most prominent face of open source the OWASP project represents an excellent ressource to stay informed and make decisions about application security.

The project also provides a comprehensive guide to build secure Web applications and Web services and many recommendations also for projectmanagers, application owners and of course C-level executives.

Labels: , , , ,

 
'The Internet is shifting to a medium that is more and more structured with a decentralized authority. Google is King of the Web.'
SubscribeSite Feed | Skype MeMy status | eMailGmail
www.flickr.com

My Photo
Name: Andreas Engel
Location: Düsseldorf, NRW, Germany

BizDev & Product Management | eCommerce, PMI, ITIL, SDE

Twitter Updates
follow me on Twitter

Previous Posts
eBay and Amazon on Collision Course
Passion for Speed: Google Chrome
Turning the Wheel - Observing the World
Leveraging YouTube's Data in the Cloud
Combining Blue and Green: Telefónica
Vodafone.de not Capable to Deliver a Stunning Web-...
Barcelona Olé!
Looking Forward to See a Mobile Web 2.0 Revolution...
Web-Apps Evolution in the Cloud
Setting a New Web-Standard with OAuth for Secure A...

Tagging Thing
Ajax | Branding | Collaboration | Diving | Entertainment | Checkout | Google | Lifestyle | Movies | Photos | Strategy | Networking | Productivity | Videos | Web 2.0

Strategy Evaluaton
Current and Future eCommerce Challenges (HTML)
Spotlight 2.0 (HTML) | (PDF MindMap)
TnT 2.0 (PDF MindMap)