Skip to main content
Home
  • Agile
  • Manage
  • Test
Register
Log In
  • Membership
  • Feedback
  • Contact Us

Report Finds Major Security Flaws in 8 out of 10 Applications

News Article

Report Finds Major Security Flaws in 8 out of 10 Applications

Comments: (0) | Fri, 12/09/2011 - 8:30am
  • Login or register to post comments
  • Print

A report by security firm Veracode made the news this week with a claim that more than 80 percent of the 10,000 applications it examined failed its security tests. Less than 60 percent of applications failed similar tests in April. According to coverage in eWeek, the drastic increase in failed tests is due to Veracode's stricter testing and newly instituted "'zero-tolerance policy' for cross-site scripting and SQL injection flaws."

The Register notes the report's discovery that "mobile developers tend to make similar mistakes to enterprise developers, such as the use of hard-coded cryptographic keys," with more than 40 percent of tested Android applications failing this test. Forty is also the magic number for government applications percent of tested applications, where forty percent of tested applications showed signs of SQL injection issues.

Meanwhile, according to a story in Wired, commercial applications are subject to other flaws, including "buffer overflow and management issues."

But it's not all doom and gloom. the Register also notes that "more than 80 percent of the apps that flunked Veracode's tests at the first attempt were successfully modified to make a passing grade within one week."

What's your reaction to these numbers? Based on your experiences, are Veracode's results surprising or typical? And, perhaps most importantly, what can we do about it?

  • Risks
  • Security
  • Security
  • Software Development
  • Android
  • cross-site scripting
  • government
  • mobile
  • SQL injection
  • xss

More like this

  • Better Software & Agile Development Conference West
  • Spike in Mobile Malware Doubles Android Users' Chances of Infection
  • Android Leads the Way in Mobile Malware
  • Malware Mayhem at MySQL.com
  • Oracle Says HTML 5 and JavaScript Will Dominate Application Development

Welcome to TechWell!

With an ever-expanding library of content by industry experts, TechWell is your source for software knowledge. The site is still growing, so please pardon our dust. If you see anything that requires our attention, please CONTACT us.

Not a member? REGISTER to join our community.
Already a member? Log In

Hot Topics

  • Most Read
  • Most Discussed
  • Most Shared
  • New Downloads

Management Myth #1: The Myth of 100% Utilization

Article by Johanna Rothman | Comments (17)
 A manager took me aside at a recent engagement. “You know, Johanna, there’s something I just don’t understand about this agile thing. It sure doesn’t look like everyone is being used at 100 percent... Read More

Edit Those Epics

Article by Johanna Rothman | Comments (23)
 I've been working with folks making their transition to agile. One of the hardest transitions is for the managers and technical leaders.Managers are accustomed to working in timeboxes. To them, the... Read More

Matt Heusser and Company Discuss "Testing is Dead"

Blog Post by Jonathan Vanian
 Do you think testing is dead? Matt Heusser recently put up a great podcast over at Software Test Professionals discussing this blasphemous topic. Read More

Passing the Baton

Article by Rinku Sahay | Comments (1)
 I was watching a relay race recently. A relay is where members of a team take turns to perform and complete a certain action or activity. In a relay race, one team member passes a baton to another... Read More

The Future Is Mobile Technology

Article by Heather Shanholtzer | Comments (3)
 A thought leader in mobile application testing, Jonathan Kohl has been a pioneer in applying effective software testing, business analysis, and design and project management on mobile application... Read More

Management Myth #1: The Myth of 100% Utilization

Article by Johanna Rothman | Comments (17)
 A manager took me aside at a recent engagement. “You know, Johanna, there’s something I just don’t understand about this agile thing. It sure doesn’t look like everyone is being used at 100 percent... Read More

Considering the Modern Technology Career

Article by Matthew Heusser
 Software development is a young field, at least compared with established professions like law and medicine. The choice to work in software is likewise a different choice. It is often made in youth... Read More

Testing Tradeoffs and Project Risk: A Case Study

Article by Payson Hall
 The project had issues. It was a two-year project intended to swap an aging legacy application for a commercial product. The vendor’s off-the-shelf software required some customization and extension... Read More

The ROI of Learning for Testers

Article by Lisa Crispin
  During my software career, I’ve spent a lot of time and effort learning new thinking and technical skills. I’ve encouraged my peers to do the same. The series that Janet Gregory and I wrote on... Read More

The Top 5 Frustrations for Project Managers

See how you can avoid management swoop-in at the eleventh hour, or creating and sending around a dreaded 200-page plan that no one has time to read once, let alone every time a change occurs. We've... Read More - Get this content

Follow Us On...

Follow us on Twitter
Twitter
Follow us on Facebook
Facebook
Follow us on LinkedIn
LinkedIn
Follow our RSS feed
RSS Feed

Sponsors

  ASTQB
  HP Software
  Microsoft
  Neustar
  SQE Training
  SmartBear Software
  Tricentis


Our Bloggers

Johanna Rothman is a management consultant and a regular StickyMinds.com and Better Software magazine columnist.

Steve Berczuk is an engineer and ScrumMaster at Humedica where he's helping to build next-generation SaaS-based clinical informatics applications.

Naomi Karten is a highly experienced speaker and seminar leader who draws from her psychology and IT backgrounds to help organizations improve customer satisfaction, manage change, and strengthen teamwork.

Lee Copeland has more than thirty years of experience in the field of software development and testing.

Lisa Crispin has worked as a tester on agile teams for the past ten years, and enjoys sharing her experiences via writing, presenting, teaching and participating in agile testing communities around the world.

Claire Moss has been testing software for 8 years. Although authoring a testing blog and articles are new for her, Claire has always had a passion for writing, which might be a strange trait for a Discrete mathematician.

Site Contents
Back To Top
  • » My Page
  • » Communities
    • - Agile
    • - Manage
    • - Test
  • » Solution Central
    • - HP Solution Center
  • » Interact
    • - Blogs
    • - Forums
  • » Resources
    • - Articles
    • - Better Software Magazine
    • - Download Center
    • - News Center
    • - Podcasts
    • - Videos
  • » Events
    • - Web Seminars
    • - Conferences
    • - Training



Techwell

  • Terms of Use
  • Privacy Policy
  • RSS
  • Site Feedback
  • Subscription Services