The Forrester Muse
for Information Management Blogs
OCT 17, 2012 4:53pm ET

Blogroll

blog

Careless Programmer Can Threaten Online Storage

Print
Reprints
Email

More and more data is stored online by both consumers and businesses. The convenience of using services such as DropboxBoxGoogle DriveMicrosoft Live Skydrive, and SugarSync is indisputable. But, is it safe?

All of the services certainly require a user password to access folders and some of the services even encrypt the stored files. Dropbox reassures customers, "Other Dropbox users can't see your private files in Dropbox unless you deliberately invite them or put them in your Public folder."

The security measures employed by these file syncing and sharing services are all well and good, but they can be instantly, innocently neutered by a distracted programmer. Goodbye privacy. All your personal files, customer lists, business plans, and top secret products designs become available for all the world to see. How can this happen even though these services use sophisticated authentication and encryption technologies? The answer: a careless bug introduced in the code.

Below is some Java code I wrote for a fictitious file sharing service called CloudCabinet to demonstrate how this can happen. Imagine a distracted programmer texting her girlfriend on her iPhone while cutting and pasting Java code. Even non-Java programmers should be able to find the error in the code below.

Fortunately (and hopefully) mature application development teams have rigorous testing processes that find security holes before devastating code like this makes it into production. If, as SugarSync says, "Your peace of mind and the security of your files are our top priority." then don't just tell me about your authentication and encryption for file access, transfer, and storage. Tell me how your testing processes will catch coding errors that could compromise security of my files.

This blog originally appeared at Forrester Research.

Advertisement

Comments (0)

Be the first to comment on this post using the section below.

Add Your Comments:
You must be registered to post a comment.
Not Registered?
You must be registered to post a comment. Click here to register.
Already registered? Log in here
Please note you must now log in with your email address and password.

Blog Archive for Mike Gualtieri

Best Sellers on Predictive Analytics
What Should You Expect from Big Data in 2013?
Psst, You Already Have Cloud Developer Skills
Predictive Analytics That Rock Your World

More from Mike Gualtieri »

Blog Index »

Where do young IT professionals (30 and under) obtain information to aid with daily role responsibilities and career development?

Trade publication websites 14%
Social media 23%
Vendor websites 4%
Vendor/community forums 7%
Newsletters 1%
Trade conferences/meetups 2%
RSS feeds 6%
Web search 44%

 

Twitter
Facebook
LinkedIn
Login  |  My Account  |  White Papers  |  Web Seminars  |  Events |  Newsletters |  eBooks
FOLLOW US
Please note you must now log in with your email address and password.