Social media and intranet case studies, best practices, & evolution by Toby Ward.
Re: Re: JavaScript opens doors to browser-based attacks
by Toby Ward
Hi Walter, This is Will O'Neill, the Webmaster of HealthyOntario.com - I work for Prescient (Toby's company) and he asked me to address your question briefly. I don't know enough about your situation to answer in detail or make suggestions, but in general terms the risk increases considerably - instead of having a firewall that blocks this kind of traffic absolutely, as a closed intranet woud likely have, you'll now have to lower that barrier and set up an authentication system for users at the gate. The risks, of course, are hackers who can read, alter or destroy data, as well as potentially introduce viruses to your system. One piece of advice I can offer is to enforce a strong password discipline among users - this means mandatory case-sensitive passwords that must use a combination of letters and numerals in nonsense combinations. This will offer resistance against programs that attempt to determine passwords. The bottom-line is that it is a risk, but you have to weigh it against the need in your organization and also consider the resources you're prepared to commit to security solutions on both a software and hardware level. Good luck with your research! Will O'Neill woneill@prescientdigital.com
Post comment:
Format Type: 
  Convert newlines
  Receive comment notifications for this article
Subject: 
   
insert bold tags insert italic tags insert underline tags insert strikethough tags insert link insert blockquote tags
Comment: 
Comment verification:

Please enter the text you see inside the graphic to post your comment:
You are not currently logged in. If you would like your user information to be displayed with your comment, please enter your login information below.
Login information:
Username: 
Password: 
If you would like to post contact information on your comment, please enter your information into the optional fields below:
Contact information:
Name: 
URL:  example: http://yourdomain.com
Email: 
Please note: email will not be displayed on the site, only for the blog owner. If logged in, URL will only be used.
   
Search
    follow me on Twitter