Michael Bargury -- Low Code / No Code Security and an OWASP Top Ten
With Michael Bargury
Michael Bargury is the Co-Founder and CTO of Zenity, where he helps companies secure their low-code/no-code apps. In the past, he headed security product efforts at Azure, focused on IoT, APIs and IaC.
Audio hosted by Buzzsprout. Nothing loads until you press play.
Episode chapters · 13 chapters
- 00:00Meet Michael Bargury: Low Code / No Code Security and an OWASP Top TenAudioVideo ↗
- 01:33Yeah. And you just got back from Global AppSec, right, inAudioVideo ↗
- 04:13Michael, so thanks again for joining us. As I mentioned, ourAudioVideo ↗
- 08:49Yeah. So, just to And sure, I want to kind ofAudioVideo ↗
- 10:15That's no-code then in that example, rightAudioVideo ↗
- 18:23Wow. Yeah, it's a whole new avenue that nobody's really thoughtAudioVideo ↗
- 20:16With that in mind, you know, I was thinking about thatAudioVideo ↗
- 23:28You have an exampleAudioVideo ↗
- 26:46You agree with that or is there something I'm missingAudioVideo ↗
- 29:34So, you've put together this new project, the OWASP Top 10AudioVideo ↗
- 36:11Michael, you have— I mean, I really love this list. It'sAudioVideo ↗
- 38:43I look at these, you've got, you know, I'm looking atAudioVideo ↗
- 42:56Yeah. So, there's a lot more here to look at, andAudioVideo ↗
About this episode
Michael Bargury is the Co-Founder and CTO of Zenity, where he helps companies secure their low-code/no-code apps. In the past, he headed security product efforts at Azure, focused on IoT, APIs and IaC. Michael’s passionate about all things related to cloud, SaaS, and low-code security, and spends his time finding ways they could go wrong. He also leads the OWASP Low-Code Security Project and writes about it on Dark Reading. Michael’s a regular conference speaker at OWASP BSides, DEF CON, Michael joins us to unpack low-code, no-code, and the new OWASP Top 10 that defines specific risks against low and no-code. We hope you enjoy this conversation with Michael Bargheri.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
We help enterprises reduce vulnerabilities through application security education for developers and everyone in the SDLC.
→ Learn more about Security Journey
Connect with Michael Bargury:
→ Zenity
→ OWASP Low-Code/No-Code Top 10
Resources
→ Zenity
→ OWASP Low-Code/No-Code Top 10
→ Robert Hurlbut
Actionable
From this conversation
- 22:41
Make secure choices easy for business users
We need to make it easy and simple for business users to make the right choice.
- 39:06
Replace personal connections in shared applications
You need to make sure when there's an application that is being used by an organization, by the organization, to make sure that the underlying connections are not somebody's personal connections.
- 39:06
Set guardrails around low-code business logic
You need to understand what business users are building and try to put guardrails around it to point them in the right direction.
- 40:24
Inventory low-code platforms and the apps built on them
You need to figure out which platforms your users are using and what applications they have built on top of these platforms.
- 43:18
Bring low-code and no-code under security oversight
First of all, we need to understand as security teams that this is business, that this is critical, and this needs to fall under our umbrella.
Transcript · 47 min conversation
0:00Chris RomeoMichael Bargury is the co-founder and CTO of Zenity, where he helps companies secure their low-code, no-code apps. In the past, he headed security product efforts at Azure focused on IoT, APIs, and infrastructure as code. Michael's passionate about all things related to cloud, SaaS, and low-code security, and spends his time finding ways they could go wrong. He also leads the OWASP Low-Code Security Project and writes about it on Dark Reading. Michael's a regular conference speaker at OWASP BSides, DEF CON, Michael joins us to unpack low-code, no-code, and the new OWASP Top 10 that defines specific risks against low and no-code. We hope you enjoy this conversation with Michael Bargheri.
0:43Robert HurlbutThe Application Security Podcast is brought to you by Security Journey. We help enterprises reduce vulnerabilities through application security education for developers and everyone in the SDLC. Learn more at securityjourney.com.
0:58Chris RomeoHey folks, welcome to another episode of the Application Security Podcast. This is Chris Romeo, Chief Security Officer at Security Journey and also co-host of the Application Security Podcast. I'm also joined today by my good friend Robert Hurlbut.
1:14Robert HurlbutHey Robert.
1:14Chris RomeoHey Chris. Yeah, Robert Hurlbut here, and I am a Principal Application Security Architect at Acquia and very excited about this topic we're going to be talking about today. It's something I've been hearing about, seeing as well in the wild, if you will. And so very, very cool.
1:32Michael BarguryVery cool topic.
1:33Chris RomeoYeah. And you just got back from Global AppSec, right, in San Francisco? So what was your kind of general impressions of that? Well, it was, it was a great time, of course, to be out there again. I think it's 3 years since they met in person. And so to see a number of folks that I already knew and meet new people as well, I think they had a really good turnout of new people for this conference. I know they had time where they asked for people to hold up hands and there was, wow, it was a good packed audience of people who were first-timers. And this topic also, this, we're going to be talking about low-code, no-code came up as well in some talks and some folks I talked to. So, excited. Excellent. Glad to hear that the conference went well. And Michael, we've made you wait long enough. And so, we like to jump right in though. We don't give our guests any time to warm up. We go right to the security origin story because our listeners are literally on the edge of their seat waiting to hear, Michael, how'd you get started in application security?
2:38Michael BarguryYeah. So, first of all, thank you for kind of inviting me here. I'm really excited. I was really excited to do this. So, I actually started with cybersecurity when I was young. When I was kind of in high school, we had people from the industry come into my high school and actually teach us about hacking. Like, they would give you an application and show you how to do SQL injection and all sorts of stuff. I actually had the opportunity to learn from Adi Shahrabani, who's today the CTO for Snyk, used to be the CEO of SkyQ. So, that was kind of a really fortunate opportunity for me. Later on, as many Israelis do, I spent some time at the IDF, and later I spent several years at Microsoft, which actually kind of shifted my perspective to enterprise security, how enterprises think about security. I got to spend several years as part of the Azure Security CTO office for the cloud, basically finding out new opportunities for Microsoft to fix security issues that are top customers were thinking about. So that's kind of how I got to both security, but then later security in terms of what is important for the enterprise or for the largest of organizations out there. Very cool.
4:12Chris RomeoSo, Michael, so thanks again for joining us. As I mentioned, our topic today is no-code or low-code. So for our listeners and, and those who are watching on the video, what is no-code and what is low-code?
4:26Michael BarguryYeah, so that's a, that's a very good question. And actually it is kind of something that is, uh, that is changing as the industry grows. Um, low-code, no-code is, is, means a lot of, a lot of things, a lot of different things for, for many different people. Uh, but when you try to think about it, and especially from the enterprise perspective, First of all, you need to make a distinction between platforms that are dedicated low-code, dedicated low-code, no-code platforms. So you have your Appians, your Mendix, your Zapier, IFTTT. Those are kind of platforms that are either a glue between different applications or they could be a way for you to create new business applications. So that's kind of one thing. And another thing entirely is where you have an existing SaaS offering. So, imagine a Salesforce, an Office, a ServiceNow, and they want to expand. So, basically, they want to— Salesforce, for example, wants to become just more— I mean, today it's much more than a CRM, right? But that's where they started and they want to expand. And so, low-code gives them the ability to expand above and beyond what they were doing earlier. Today, Salesforce is a platform to develop applications. And so you have these low-code, no-code platforms that are dedicated platforms like application development platforms. And you have low-code, no-code developed that started as an extendability feature around existing offerings like CRM or ERP. What, what we're seeing, uh, in, in recent years is that both these types of low-code, no-code platforms, while they started by allowing professional developers to build faster. So, you're an application development team, there's a lot that you have to do. Low-code, no-code platforms started as a way for you to basically accelerate your development processes. So, you You would, for example, people, when people use Salesforce, they used to go to a partner. The partner would customize Salesforce for them, and they used to do it with code. So Java, Apex, and other places that holds as well. When you, the reason to bring low-code, no-code into the mix is just because it makes things easier. So there's a lot of building blocks you can pick up and use. You can, there are processes that are built for you, and some of the—
7:02Chris RomeoYeah.
7:03Michael BarguryThe database could be managed for you, the authentication could be managed for you. So that's a way to accelerate. That's how it started. On the dedicated platform side, there are kind of, again, it's not about extending the CRM, but it's about creating a specific business process. So you could, for example, make sure that you streamline everything around receipts or reimbursement of kind of a, expenses. That's an example of something that people need to automate. And so they, they, they use these platforms to accelerate their development. The number one thing that we've seen change for both these types of platforms in the last 2 to 3 years is that rather than focusing on the professional developers, they have shifted focus to business users. And of course, this is not new. People have been trying to empower business users Ever since, I mean, since forever, right? So, and by the way, some of this has already worked. So, think about Excel. This is something that has empowered business users. It's actually created new jobs. And it also shows you the kind of opportunity that there is. The amazing thing about low-code, no-code today is that platforms are so sophisticated they are actually successful in bringing the same kind of power that they used to bring only to professional development teams. Now they bring this power to the hands of the business users.
8:38Chris RomeoTo everybody.
8:39Michael BarguryEverybody can build their own applications. That's just an amazing property of those platforms, and that's why they are so important.
8:49Chris RomeoYeah. So, just to And sure, I want to kind of read back some of what I heard because I'm still processing this idea of low-code and no-code myself personally. I'm trying to figure out what buckets I put things into. And so, you mentioned Excel. So, Excel's macro kind of language and the ability that— so, that's an example of low-code, or is that no-code? No, I would say that's code, right?
9:20Michael BarguryYeah.
9:20Chris RomeoSo go ahead.
9:20Michael BargurySo that might be a bit of a confusing example. The Excel example is important to figure out what happens when you put more power in the hands of business users.
9:33Robert HurlbutOkay.
9:34Michael BarguryBut low-code is actually a bit different. Low-code is about basically simple interfaces, drag and drop. There's a marketplace of widgets you can use. There's a whole bunch of connectors that will connect anywhere for you. And it allows you to very quickly build an application. So you take information from your CRM, you combine it from information with your custom database or maybe your email address, and then you output the merged results into a spreadsheet. And instead of doing that with code, you do this with drag-and-drop building blocks.
10:14Chris RomeoSo, that's no-code then in that example, right? If I'm just dragging and dropping things into a GUI and I'm dragging a box that says it's going to connect to Mailchimp for email marketing purposes to collect, and I drag another box that's for my CRM, that's going to— then that connection is going to make those email addresses get recorded in my CRM. So, that's no-code then. From a low-code perspective, Are they, are these the same thing? Is no-code, low-code, is it, are these, are these synonyms or are they slightly different categories? I'm sorry to, I'm pressing, but I'm trying and it's only because I, I really don't understand the difference between the two and I wanna make sure I walk away going, ah, I under— I wanna, I want the light bulb to go on over my head here.
10:58Michael BargurySo the, the traditional kind of, uh, the traditional distinction is that no-code is really all about drag and drop.
11:06Chris RomeoYeah.
11:07Michael BarguryAnd low-code is drag and drop with extendability.
11:11Chris RomeoOkay.
11:11Michael BargurySo, for example, you can create your own steps. If there's no connector, you can create one yourself. You can plug in custom code to do things that are not possible. But when you think about an enterprise, when a no-code platform becomes enterprise-first, the enterprise would push it to add in extendability features. Right. Okay. And so that's how no-code becomes more like low-code. And from the other perspective, low-code started as a way for professional developers to, to do things with customization. But of course they want to reach to the business users and so they're making things easier and so they become more like no-code and that's why it's a bit confusing.
11:55Chris RomeoYeah, I think it makes sense. You, you've, I, I've got it in my brain. I've got it like segmented into 2 different categories here. So thank you for that explanation. That's really, Really helpful to— because when we start talking about the security, the application security risks that you've identified in the new top 10 you created, I think it's helpful to have that frame of reference. But I want to talk about a couple of examples that you shared, a number of different stories of how low/no-code intersects with security. And so, let's start by, tell us about this example with the enterprise users using low/no-code to bypass DLP. And read emails over Gmail. So yeah, I'd love to hear this story.
12:35Michael BargurySo, this is actually, this is a recurring story. Every enterprise I ever worked with had some sort of this problem in their organization. So, let me kind of, let me share the example. Basically, security teams have been trying to prevent email exfiltration or exfiltration through email since forever, right? And so, you have, you can put something on your email server, you can use some sort of a DLP solution, and they would look for emails that are being exchanged with another domain. Of course, business users will always find their way around these controls. And so, this is where low-code kicks in. So, instead of forwarding the email, forwarding your email to your personal Gmail, for example, which would be caught by a DLP and blocked, what if you simultaneously, you log in to your corporate email and to your Gmail account instead? And then instead of forwarding the emails, you copy the content of each corporate email and you save it to your Gmail account. And so that's something you can do manually, right? You can do it one time. You'll open up 2 browsers. You'll copy things between here and then. But what if you can use low-code to do that automatically for you? And so what we found is that users create these automations that subscribe to every new email that arrives to your corporate account. And when that email arrives, they copy the entire content, and save it as an email that they send to themselves in their Gmail account.
14:20Chris RomeoYeah, it's brilliant.
14:23Michael BarguryAnd because the data is being copied and nothing moves kind of on the wire, right? Basically, there's no way for you to catch it because the only way to really identify that this actually happened is to look inside the local platform that is performing this movement of data. Nobody else knows that the data moved from corporate to a Gmail account.
14:47Chris RomeoWow. Tell us the story about what you've seen with no-code used to operate malware, criminal kind of organizations, because that's another fascinating connection you're sharing here, and I want to know more about that.
15:04Michael BargurySo, when you think about low-code or no-code today, There are some properties that are important to understand before you can understand why it's important for an attacker, why it's a good place for an attacker to focus on. First of all, this is SaaS. So, like any SaaS, security controls are lacking. It has compute built in because this thing is operating on its own. It is also, by definition, connected to business-sensitive data. So, if you have, for example, Power Platform, Microsoft's low-code platform, it's wrapped around everything Microsoft. So, Office, it connects to Azure, wherever you'd like. And so, it's a very good place to easily connect across the enterprise. And so, this is actually a story that was identified by Microsoft, Microsoft Detection and Response team. Basically, They were called in to help an organization that understood that they were under some sort of a breach, but they couldn't find the attacker. They couldn't kick them out of the network. And they actually looked inside the network for more than 6 months to identify the attacker. They were not able to find where the attackers were. I mean, they found some parts, but other parts were still there. After more than 6 months, they found a low-code automation that did something kind of very simple. On a schedule, it would use the eDiscovery tools for the Microsoft tenant to look around the tenant inside SharePoint and Teams and email for secrets, for sensitive data, and would just collect all of that data. And then send it off to an exfiltration endpoint. And that's kind of a very simple automation, right? A couple of steps. You use these features, you send the information out there. But because this automation lives inside the low-code/no-code platform, specifically here, Microsoft Power Platform, it's not within your tenant. You won't find the network traffic going to that exfiltration endpoint.
17:20Robert HurlbutRight.
17:21Michael BarguryIn order to figure out that this is happening, you need to actually know that this automation even exists and then figure out what it's doing. And so when they finally found it and they did the investigation, here's what they found out. First of all, the attackers were able to gain access by kind of a simple phishing campaign, and this got them access to an admin account within that organization, so a global admin for the AD tenant. But then, instead of doing the thing that kind of— of going down the normal route of installing malware, moving laterally through the network, which is where security teams focus as well, instead of doing all of that, they simply created the automation that they just elaborated on. a moment ago. And so, this made it basically the perfect way to maintain persistency because nobody's looking.
18:23Chris RomeoWow. Yeah, it's a whole new avenue that nobody's really thought about. And so, I just want to clarify for our audience, there are many, many positive ways to use low-code/no-code. We've just shared 2 stories, examples from Michael's history. of things that I don't want someone to be like sitting here right now going, I'm never using low/no-code. It's only used by criminals and exfiltrators of email, right? Like, there's a lot of positive cases for enabling the business users to be able to create connections between different platforms and add value to the business. It's not just for criminal activity.
19:00Michael BargurySo, actually, I think that's a That was a really good point to bring up here. I work with a lot of large organizations and my company as well, and also as part of the OWASP project. The amount of business value that business users are able to bring into organizations with low-code, no-code is just amazing. You're seeing people from HR, from finance, from sales, from customer success, They are finding problems that prevent them to succeed as a business, and they just fix it. They don't wait for anybody else. They can just move forward, and the value is enormous. But that's also why it's so important to do things in a secure way, because, because once things become business critical, security has to be involved.
19:54Robert HurlbutKeep security top of mind with continuous application security training for your developers. Security Journey offers bite-sized lessons with hands-on interactive training for all roles in the SDLC. Give your admins the ability to use pre-built or custom training paths with easy-to-use tracking and reporting. Visit securityjourney.com to see our solution today.
20:15Chris RomeoAnd with that in mind, you know, I was thinking about that, and, and again, I've been looking at this for probably a couple of years, just seeing it continue to rise on in terms of usage and so forth. But I also have been thinking about the security perspective. But for our audience, why is it different from a security perspective?
20:40Michael BargurySo, I mean, one of the things that, one of the things that you see when you, when you were having, so when we had conversations with security professionals that are in charge of basically application security or security architects, and they are trying to see whether they can expand their existing approach to low-code/no-code, you very soon find out that all of the basic building blocks that you're used to build your security strategy on, they don't really exist for low-code/no-code. So, you're used to code scanning, There's no code to scan. You're used to runtime monitoring. This is running on somebody else's cloud with no way to intercept anything. You're used to be able to do security reviews. The scale of low-code/no-code is enormous. We're talking about between 10x and 100x in the number of applications being developed. So, manual processes won't work. Security reviews won't work. And you're also used to the fact that the developers themselves, they are security savvy. So you teach your developers security, you try to evangelize security with your professional developers. Now think about somebody from the customer success team creating a connection, and they need to choose between a secure and insecure connection. I mean, it's not their job. They are not supposed to know how to store credit cards. They need to fix their business problem. They are the experts at the business problem. But we've kind of left them exposed to choose the things that we expect developers to choose. And even for developers, we have so many things that help them identify mistakes and that protect them. And for business users, it's simply not there.
22:41Chris RomeoYeah.
22:41Michael BarguryAnd so, it's both in terms of the tooling that simply will not work, but also, and much more importantly, this is the scale and the types of developers that are building these applications. They are completely different. So, we need to basically work together with them. We need to make it easy and simple for business users to make the right choice. We need to put guardrails around—
23:08Robert HurlbutYeah.
23:09Michael Bargurythe way that business users are operating so they don't have to think about security. But when something might happen, when they create some sort of an issue, we need to be able to guide them in the right direction in a language they understand, which is of course very different from a language that a security professional would— a developer would understand.
23:27Chris RomeoDo you have an example? Like, what would you say to someone who's building a no-code, low-code solution and help them understand a security issue, let's say?
23:42Michael BargurySure. So, I think one of the things that, one of the examples that I find most illuminating is that when you look at the way that, I mean, maybe I'll take a step back here just to figure out why this happened, why this happens. Low-code, no-code platforms try to expand within organizations, right? They need to be able to I mean, it needs to be easy to create these applications. But when you think about professionally developed applications developed by professional developers, every time they create a new application, there's a process to acquire permissions for that application, right? You need to set up an identity for the application, and then you need somebody from IT or security or somewhere to approve that the application could exist. And it can do certain things. If any low-code/no-code application would need to go through the same process, there would be no way for people to develop, for this to kind of rapidly expand within the organization. And so, the way that this is handled is that low-code/no-code platforms allow you as the maker of an application to embed your own identity within the application. And so let's say I create an application that is plugging in that data from Salesforce. I don't have the ability to now create some sort of a service account to Salesforce. Instead, I will choose my own. I will log into Salesforce. The authentication token will be saved somewhere. And then you get a kind of a magic happens and the low-code platforms allow you to share that authentication token or that authenticated session with somebody else. And so the way that this ends up happening is that the maker would create an application, embed their own identity within that application, share it with somebody else, and then every user that uses the application ends up using the maker's identity in every underlying call. And so when you think about it from the network perspective, from the SOC perspective, There's no application, right? There's this single user that is being used across the enterprise to do a whole sort of queries. There's no way for the network logs to show you or for the API logs to show you that there are different users behind this application or that this application even exists.
26:12Chris RomeoSo, Michael, that sounds to me like a flaw in the platform though. If the platform allows me to drop in an authentication token and then use that authentication token, share it with other entities, or it becomes a central authentication token that other users in my organization can use, to me, that sounds like a platform issue in that there's a lack of security thought that went into the architecture of the platform itself that's providing the service. So, what— how does that—
26:45Michael BarguryYeah.
26:46Chris RomeoDo you agree with that or is there something I'm missing?
26:48Michael BargurySo, it's valid criticism on the way that platforms have been built. But the reality is that today, this is the way the vast majority of low-code, no-code platforms operate. And for good reason. They operate this way because there are valid use cases to share those connections. So, imagine a development team, They set up their connection to the ERP one time and then everybody in the development team can use it. The problem becomes when this easy way to share credentials becomes something that business users can pick up and use. For example, Microsoft has this Microsoft Power Platform, has this notion of a default environment. That's kind of the— kind of imagine you open up the platform for the first time. That's where they— that's what will open up for you. Users can, I mean, by mistake or not, they can create a connection and share it across the organization, which means with everybody that has access to the default environment. So, in some cases, you'll find connections to, you know, somebody's Outlook account. somebody's Teams account, and they're just lying there. So, it's true that the way that this application— I mean, every new platform has new risks that come with it. There are valid reasons to share connections in order to create applications that are kind of robust, and you only need to create those connections once.
28:34Chris RomeoYeah.
28:35Michael BarguryBut it's about— but the customers or the people building the applications, they are in charge of what they actually build. They are in charge of making sure that they build things in a secure way. And so, the OWASP Top 10, for example, is focused on that, on the customer side of the shared responsibility model rather than the platforms.
28:56Chris RomeoYeah. And I could see if I'm building a no-code platform, my first priority is simplicity and ease of use for the business users. Me, as a security engineer, my first priority is not ease of use and simplicity for the business users. It's protecting the data that we have in the system. And so, it sounds like there might be some tension in the platforms that exist right now. But I mean, we've kind of teased out the OWASP Top 10, the new Top 10 you've put together here. And I think we've teased it out long enough.
29:32Michael BarguryIt's time to dive into it. Yeah.
29:34Chris RomeoAnd so, you've put together this new project, the OWASP Top 10 for no-code and low-code specifically. And so, let's just dive into how'd you come up with this top 10? Why this top 10? Did you just, you know, how'd you come up with a list of 10 things that are on this list today?
29:56Michael BargurySure. So, When we started working with, when we started focusing on low-code, no-code, and how do you think about it from a security perspective? And we worked with many different organizations, we're still working with many organizations, some large, some smaller, some across the industry. And one thing that has become clear is that it's really important to make it easier for the entire industry. And we need to understand what are the top risks and how do we think about low-code, no-code security? What are the things that we, to your point earlier, what should we ask the platforms to do? And what is our job as the people using low-code, no-code? Because, I mean, you remember when we started kind of thinking about cloud and cloud security, everybody was saying, hey, AWS, Azure, GCP, you should solve all of the security problems in the cloud.
30:56Chris RomeoYeah.
30:57Michael BarguryOf course, today we understand that that's not really what's going to happen. There's a shared responsibility model. They will build secure building blocks. You're in charge of what you're building. The same thing applies for low-code, no-code. But then there's a serious question. I mean, okay, so I want to be in charge. What do I need to look out for? So what are the things that people are doing that create vulnerabilities? For my organization. So we started working with a lot of these, uh, large corporations, and actually, uh, some of the kind of the, the top 10 actually emerged from, uh, scanning, uh, hundreds of thousands of low-code, no-code applications. Um, and this is, uh, information that comes from, from Zenity, from, uh, from my company. And so with this, with these scan results we've been able to identify what actually happens within large organizations and then categorize it in a way that can drive meaningful mitigation. And we've also been very fortunate to have other people from the industry joining us in the OWASP project. So we have people from Palo Alto and from Microsoft and others kind of have started collaborating with us recently. Because this is— there's really a lack of— there's really a need to understand better where we should focus. And so the OWASP Top 10 for low-code/no-code is focused on what can happen when you build low-code/no-code applications incorrectly, what kind of problems you can introduce into your business. And the important thing is that most of these problems are about the business logic of the application. We are not looking for kind of CVEs or anything that is kind of very, very clear from what we used to know in application security. We're looking for applications that simply don't make sense. They might be sharing identities. They might be moving data outside of the organizational boundary, but it's all about the business logic of the application.
33:05Chris RomeoI love to hear that. we have something focused on the business logic because so much of AppSec has been focused on the non-business logic. Like, Robert and I are both, you know, gigantic proponents for threat modeling because threat modeling, the value in threat modeling is being able to— you can't write a tool that detects business logic in regular code. So, it's a bit of a soapbox for me. I'm gonna step down off my soapbox now. But I really, I love the fact that you're talking about, hey, this is a top 10 list that's focused on business logic problems. Because that's really where a lot of our vulnerability lies today. You know, you look at— I'm really going to go off on a soapbox moment here, but, you know, you look at the— a lot of people have been studying the exploitability of CVEs.
33:49Michael BarguryMm-hmm.
33:51Chris RomeoAnd I believe some of the research that I've seen that a lot of the CVEs we get worked up about aren't exploitable. You can't— nobody can exploit them. But we all get excited and we make a marketing page for and a logo for some new CVE and everybody gets all spun up and, oh, well, it's actually not really that exploitable in production applications. It's kind of code that's hidden. You can't really get to it. And so, the fact that you're talking about business logic is just a powerful moment that really resonated with me. Didn't mean to interrupt, but I went off on a bit of a tangent here.
34:22Michael BarguryI think that, I mean, one of the things that is most exciting for me about the intersection of low-code, no-code, and security is that, I mean, low-code/no-code is really something that is trying to replace this kind of copy and paste integration. And so, think about business users kind of just moving data from here to there, sharing credentials. These are things that as security teams, we never had visibility into. And it's not like we didn't try. Like, we tried with DLP, we tried with a whole bunch of things. Nothing worked. Now, If we push— if, if we, uh, if— so for the security perspective, imagine that now everybody uses low-code, no-code to do these kind of integrations. All of a sudden, there's somewhere you can ask, you can ask questions, you can go to this platform and ask, hey, what are my business users doing? There was no API to do that when people were just copying data. So if we do this right as security teams, if we plug into those platforms And if we are the ones that are pushing for business users to enable those platforms, to use those platforms, this will bring us a whole level of visibility we never had as security teams to understand how the business actually operates. So, there's a very— there's huge opportunities for us as security teams to finish off in a place much better than where we started. Yeah.
35:48Chris RomeoI just have one fear, though. If we get so far deep into no low-code, We're going to put Stack Overflow out of business because that's where people go to copy and paste solutions right now. Like, I just had this epiphany. I'm like, you know, that's where everybody goes to get their bad, their insecure code these days. Their sample code and with all the comments still left in and all that.
36:11Michael BarguryYeah.
36:11Chris RomeoSo, Michael, you have— I mean, I really love this list. It's the OWASP Top 10 for low-code, no-code, security risks. And the first security risk that you have listed is account impersonation. Could you take us through that a bit?
36:28Michael BargurySure. So, account impersonation is focused exactly on the risk that I alluded to earlier, where users can basically use somebody else's identity or share their own identity within an application. And let me give you a concrete example. I kind of touched on that a few more, kind of a few minutes ago, but let me give you a concrete example. So with one organization that we've been working with, they had their customer success team, basically they had a problem where people were trying to help with the business case, with the customer support case, but they didn't have the right context because they didn't have access to the customer success kind of software. So They were not able to understand what happened with the customer before. The customer success team created an application that allowed every user to get information about the cases that they were tied to. If you help with a specific customer case, you can go into this low-code application built by the customer success team and fetch information about the relevant customer. Now, the way that this happened, that this worked, is that the customer success manager just plugged in their own credentials to the application. And so everybody was underlying behind the application was using that customer success manager's, their own identity to fetch information from the, from the customer database. Now imagine this from the SOC perspective. Actually, you don't really need to imagine because the SOC got an alert that identified that there is one user going to the customer database from multiple IPs, from multiple different machines across the enterprise, fetching information about different customers. This looks like a hack, right? And there's no way, again, to find out that there's actually an application behind it. So, of course, they reach out to this person from the customer success team, which— and it took them a few moments to understand, hey, this is actually what's going on. So, people are using this user's own credentials by using this application without even knowing it.
38:42Chris RomeoSo when I look at these, you've got, you know, I'm looking at one of these examples. You've got a description which you just shared with us, a couple of example attack scenarios that we've unpacked a few of those. Then you've got this section called How to Prevent. And so give us some context on how to prevent account impersonation. from what you've described in the top 10 here?
39:06Michael BargurySure. So, preventing these kind of, preventing low-code, no-code issues, because the issues are about the business logic, the prevention is about the business logic too. It means that you need to understand what actually business users are building and try to put guardrails around it to point them in the right direction. So, some platforms have a way to limit credential sharing. Some platforms have a way for you to, for example, you could say nobody can share a connection with the entire organization, or you can just review the list of connections that have been shared, I mean, across different users. Another thing that you can do is that most of these platforms do have a way to do things kind of the proper way. So, you can use a service account in order to kind of embed in this application. It's simply a matter of whether you have done this or not. So, you need to make sure when there's an application that is actually being used by an organization, by the organization, to make sure that the underlying connections are not somebody's personal connections.
40:23Chris RomeoOkay.
40:24Michael BarguryAnd so, for you to do that, you need to figure out which platforms your users are actually using and also what applications they have built on top of these platforms. Okay.
40:37Chris RomeoSo then, the third one on the list, just so we can expose the listeners to a little bit more from the list, I mean, their homework is going to be to go read the list and internalize it and understand it. But number 3 is data leakage. So, give us some perspective on data leakage.
40:55Michael BargurySo, a lot of low-code/no-code applications move data around. So, applications are, of course, only as impactful as the data that they touch and the identity they do it with. And so, you have lots of applications that are subscribing to changes on one endpoint. So, for example, every new file on a SharePoint list, and then they'll kind of crunch that file and maybe send a notification in Teams. And so data could be moving from SharePoint to Teams. Now, there's a large question there. Which organization owns that Teams instance and which organization owns the SharePoint site?
41:38Robert HurlbutRight.
41:39Michael BarguryBecause it's fine that it's kind of, I mean, both are Microsoft, but do they belong to your organization? And so in many cases, we find, We find that low-code platforms are used to move data outside of the organizational boundary. By the way, a lot of time it happens by mistake. So somebody would create a useful application and it would just be easy for them to use a spreadsheet in their own personal Gmail account to hold some of that application's data, because why not? I mean, the platform allows it. And so in many cases, you'll find that there's a mix between business identities and personal identities, but also business data and non-business data. And even within the business, I mean, especially in large enterprises, there's a real distinction between business from one business unit, another business unit, types of sensitivity for that data, right? Low-code, no-code platforms don't really comply with that. They connect wherever you connect them and they allow you to basically, again, copy and paste the data automatically, and so your existing controls will not be able to catch it. So, we do find this kind of again and again, and the bypassing DLP with email forwarding is one example of that happening.
42:56Chris RomeoYeah. So, there's a lot more here to look at, and as Chris said, definitely for our listeners, go take a look. But that leads us into our final key takeaways and call to action. So, Michael, for our listeners, do you have some good key takeaways as well as a call to action for us?
43:18Michael BargurySure. So, I think we covered a lot of ground around low-code, no-code, and I recognize that in many cases, people are still, I mean, from the security perspective, this is a new area. Right. The main thing to understand, or the main thing we need to— of course, as security teams, our job is to enable the business, and our job is to make sure that there is no new risk introduced into the organization, but the business can continue to operate. Business teams today are using low-code, no-code. This is not a choice we get to make. I mean, the largest platforms out there are embedding low-code/no-code within their existing offerings, and business units are buying low-code/no-code as well. This is a good thing. It's about enablement. There are 10x to 100x more business users than pro developers. This is a great thing for the business, which is the most important thing. But of course, We need to do things in a secure way and in a responsible way. And so, first of all, we need to understand as security teams that this is business, that this is critical, and this needs to fall under our umbrella. So, if we're leaving it out there for business teams to do on their own, we are failing to find the risks that they are introducing. And of course, they will introduce risks because business users are not security professionals.
44:52Chris RomeoRight.
44:53Michael BarguryAnd the other thing that— and once we understand that this is critical and this is something that needs to fall under our umbrella, of course, we need to guide those business users to make it easy for them to make the right choices. And by doing that, we will get kind of— we'll get so much more visibility than we are used to getting on how our business actually operates. And even more than that, I mean, as security teams, we always try to get buy-in from the business to kind of get on board with security initiatives. This is our chance, right? Business users are— they need our help right now to do the things that they need to do in a correct way. They don't want to be scared about the security implications of the things that they're doing. And so this is our chance.
45:45Robert HurlbutYeah.
45:45Michael Barguryto show them that we can provide value and also to get their buy-in, to get on board with the security team.
45:52Chris RomeoYeah, partnership with the business between security and the business is really going to be the true metric of success here for low-code, no-code in the enterprise. Like, if you don't have that partnership, it's just going to be a battle the entire time. It's going to make a lot of people unhappy. So, Michael, thank you so much for educating us About no-code, low-code, and, you know, your experiences and stories as you've seen it play out. And then thanks for your work on this new OWASP Top 10. I think it's very valuable, and I've learned a lot about this. I'm going to go study that list more closely now, now that I've got this conceptual framework for how all these things fit together. But we really appreciate you being a part of the podcast and sharing your knowledge with our listeners. So thank you so much.
46:41Michael BarguryThank you very much. This has been a lot of fun.
46:44Robert HurlbutNone of the top 50 university programs teach secure coding in their curriculum. At Security Journey, we help enterprises reduce vulnerabilities through application security education for developers and everyone in the SDLC. With over 400 up-to-date lessons created by industry-leading security experts and a programmatic approach that creates security champions, Our program has increased AppSec knowledge as much as 85%. Visit securityjourney.com to try our training today.
7,290 words · transcript by assemblyai
More on OWASP Top 10
View all episodes →- July 23, 2024 · 52 minAndrew Van Der Stock -- The New OWASP Top Ten
- July 25, 2017 · 44 minDave Ferguson -- The OWASP Top 10 Proactive Controls
- May 30, 2017 · 31 minChris and Robert -- Controversy within the OWASP Top 10 RC