Debating the next version of the criteria
The Plynt Certification Criteria is one year old. We’re examining the cuts and bruises, re-reading customer feedback and debating the next version of the criteria.
The most heated discussions are around:
- Is criterion #20 “New authentication token on log in” really required?
- Should we consider low risk threats in criterion #2, “Defend against Threat Profile”?
- How should we certify modules that integrate with other apps?
Criterion #20 has received most feedback as being too stringent, and tough to solve. Basically, #20 insists that the token used to track an authenticated session must take a new value after login. Seems obvious, but many platforms including JSP and classic ASP do not change the value of the session cookie on login. This is vulnerable to session fixation, and a variant we described 2 years ago. The debate is whether session fixation and the variants are serious enough to make this mandatory for certification.
Criterion #2 is criticized as being too broad, that it covers even low risk threats if the threat profile is really comprehensive. The debate is how to deal with low risk threats - who decides if a threat is low risk, what framework should we use.
And, what’s the best way to certify modules? In some of our tests, the app did not have a login page - the app was a module that plugged into other apps. In such cases, should we test the full app before certifying? Or exclude the the criteria related to authentication.
It would be great to hear your thinking. Please mail me your feedback at: firstname.lastname@plynt.com. I shall keep you updated about the criteria.
Plynt provides penetration testing and code review services to clients worldwide. If you are interested, please contact us for a quote. We’ll get back to you within one working day.Add yours.closed for this post.
Monthly Archives
- September 2008
- August 2008
- July 2008
- May 2008
- April 2008
- March 2008
- January 2008
- December 2007
- November 2007
- April 2007
- March 2007
- February 2007
- January 2007
- August 2006
- July 2006
- June 2006
- May 2006
- April 2006
- March 2006
- February 2006
- November 2005
- October 2005
- September 2005
- August 2005
- July 2005
- June 2005
- May 2005
Syndication
You can read full entries of Palisade Blog using an RSS reader. Use this link —



