Google Site Search

Google
 

Monday, July 23, 2012

PicketLink and Salesforce/Google Apps Integration

Marek Posolda from the GateIn team has created an excellent article on integrating salesforce or google apps with JBoss.  It is done via project PicketLink.

The article is at https://docs.jboss.org/author/display/PLINK/3rd+party+integration

Marek also talks about GateIn integration with Salesforce and Google Apps using PicketLink at https://community.jboss.org/wiki/GateInSSOIntegrationWithSalesforceAndGoogleApps

References

GateIn SAML Integration Wiki

Monday, June 11, 2012

LinkedIn has a wake up call

All the IPO fun news - soaring personal assets - increasing cash pile must have gone a bit sour at LinkedIn now. They have probably started living on earth now, like the rest of us. I am referring to http://blog.linkedin.com/2012/06/09/an-update-on-taking-steps-to-protect-our-members/  and http://www.nytimes.com/2012/06/11/technology/linkedin-breach-exposes-light-security-even-at-data-companies.html

I have been a LinkedIn member since inception. It feels like close to decade+. I respect and utilize their services on a daily basis. Their advances in technology primarily big data analytics impresses me.

But when customers/users provide you their information, then it is of utmost importance to safeguard it. LinkedIn failed to do that. But they are not alone. Everyday, we hear some data breach. The fundamental problem is that there is no easy way to secure anything. Passwords are useful to achieve the minimum level of security, with minimum set up. But they are not the best forms of security. Working toward preventing data breaches should be part of a daily routine.

The blog post from Vicente is very assuring. In the next few years, LinkedIn will probably have fewer news reports about data breaches. Hopefully, Ganesh Krishnan (from my alma mater, BMSCE) can shine.

What LinkedIn needs to do is take their advances in big data analytics into security intelligence. Salting/Hashing passwords is just the first step. You should incorporate device registration as well as use security analytics to thwart future breaches. Please be the first to show us the way with big data security analytics.

Good Luck to LinkedIn!

(Now can we please do something about the "Who viewed your profile?" leaks on LinkedIn on mobile apps?).

Sunday, May 27, 2012

When Access Control Systems Fail or are Absent,

you can have squatters at your company. And they are not in camp sites in your parking lots or dressed differently - they mingle and coexist with your legitimate employees. How cool is that. :)

Examples: 

1.  19 Year Old Kid builds a startup squatting at AOL.
2. Young Steven Spielberg squatting at Universal Studios for 2 months.

The story of Steven Spielberg claiming that he squatted for 2months/years is rebutted in the media. It is a possibility. :) (http://www.anecdotage.com/index.php?aid=14372)

Another example of studio squatting http://en.wikipedia.org/wiki/Daedalus_Howell#Controversy


So, give some love to access control systems. :)