The subtler points of Plynt
It’s almost a month now since Plynt was launched - the security certification standard for applications. Plynt came into existence when a handful of people got together and thought of having a certification program for web applications.
Why a certification program for web applications? Being a part of the Plynt team has helped me more in understanding why a certification is necessary and how it benefits an app. Well an app that has been certified as secure against a certification standard is more reliable and trusted. It provides an extra measure of credibility as a well-thought-out certification standard would have considered even subtle points.
And there are a lot of subtle points in the Plynt standard. Some of my favourite ones are:
- Protect secret questions from guessing attacks
- Password not stored in plain text for “Remember Me”
- Old password required before changing password
- New authentication token on log in
- No sensitive data in error messages
Here’s an example of how subtle points can be overlooked. A few days ago I was talking to a developer whose application I was about to test. Even before I could start testing, the developer said he was sure I wouldn’t find any vulnerability. The next moment, as I entered an incorrect input, there came a nice little error message with enough details to let me to break into the application. Sometimes it’s missing the small things like that which make a huge difference.
So tell us, what are the subtle things the Plynt Standard has missed?
Plynt provides penetration testing and code review services to clients worldwide. If you are interested, please contact us for a quote. We’ll get back to you within one working day.Add yours.closed for this post.
Monthly Archives
- September 2008
- August 2008
- July 2008
- May 2008
- April 2008
- March 2008
- January 2008
- December 2007
- November 2007
- April 2007
- March 2007
- February 2007
- January 2007
- August 2006
- July 2006
- June 2006
- May 2006
- April 2006
- March 2006
- February 2006
- November 2005
- October 2005
- September 2005
- August 2005
- July 2005
- June 2005
- May 2005
Syndication
You can read full entries of Palisade Blog using an RSS reader. Use this link —




Does the word "Plynt" mean anything? Google search indicates that it is some kind of a material for making weapons or something but I could not not pinpoint what it exactly means.
And oh... do you guys have a feed for comments. I have been leaving a lot of comments on different articles and it is a real PITA to keep track of each one of them individually.