Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    RSS Security Deadline – 1

    Written by

    Jim Rapoza
    Published September 25, 2006
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      As we here at eWEEK Labs evaluate the next generation of Web browsers, operating systems, collaboration tools and other interactive applications, one feature keeps popping up again and again—namely, integration with RSS feeds.

      RSS integration pretty much already has become a must-have feature for a whole host of products. Not having RSS integration is almost like not being able to use the Web at all.

      And I can see why many developers and businesses are flocking to support RSS. In addition to their popularity as the delivery method of choice for core Web 2.0 products, such as blogs and podcasting, RSS feeds have great potential for reliably delivering a wide assortment of content, files and even applications.

      But during the last year or so, many people have been asking an important question: Is RSS secure?

      Its vital that this question be answered in the next few months—before Microsoft releases its Internet Explorer 7 browser, which makes it much easier for novices to subscribe to RSS feeds, and before it releases Vista, which has RSS support built in. Both releases will have malware purveyors looking for ways to exploit the products RSS integration.

      Looked at in its simplest form, theres nothing about RSS that should make it hard to secure. Based on XML and using standard Internet transmission techniques, RSS can tap all the authentication and encryption technologies that are used to secure any Web-based content.

      However, RSS could become a major avenue of transmission for the bad stuff—namely, spam, Trojans and spyware.

      Many other Web 2.0 technologies are already dealing with their own forms of spam, with one recent report stating that a very large percentage of blogs on the Web today are actually spam blogs, or splogs.

      On a one-to-one basis, spam through RSS is hard to pull off, since a user receiving lots of spam through a feed will simply unsubscribe fr-om that feed. However, the increased use of feed–aggregating sites makes it more likely that enterprising spammers will figure out a way to deliver their wares interspersed with legitimate feeds. Automated aggregating tools based on search terms are even more likely to be exploited by spam.

      RSS almost will certainly face spam problems, although, in my opinion, not to the level that e-mail currently does. The much bigger security concern when it comes to RSS is the use, or misuse, of the RSS enclosure tag.

      The enclosure tag, which enables podcasting and videocasting, makes it possible to deliver files through a feed. And the way this is implemented in RSS is very flexible—an RSS feed doesnt care what the file type is. A file linked in an enclosure can be an MP3 audio file, an MPEG video file or even (insert ominous music here) an executable.

      There really isnt anything stopping someone from delivering malware such as viruses or spyware through an RSS feed enclosure tag. Some will say that this is unlikely to happen, as people will know from the feed where the content is originating. But recent experiences with malware delivered through Web sites show that getting bad content onto legitimate sites isnt a problem for the bad guys.

      So far, we havent seen many cases of RSS being used as an avenue for security attacks. But once RSS is an integral part of the Microsoft browser and operating system, all that is bound to change.

      So what should be done? Should businesses plan to ban RSS subscriptions? Should the RSS standard be changed to make it less attractive to hackers (and also less useful for everyone)?

      I dont think so. Many in the RSS community have been discussing these problems for a while now, and aggregators and tool vendors are taking steps to make it easier to detect unusual feed activity. And the last thing we want to do is cripple the functionality of such a promising technology.

      So RSS feeds arent completely secure. But then again, what Internet-based technologies are?

      Its pretty much inevitable that there will be security problems involving RSS feeds. But as long as users, vendors and the RSS community are vigilant, RSS wont become a security problem itself.

      Contact Labs Director Jim Rapoza at jim_rapoza@ziffdavis.com.

      Jim Rapoza
      Jim Rapoza
      Jim Rapoza, Chief Technology Analyst, eWEEK.For nearly fifteen years, Jim Rapoza has evaluated products and technologies in almost every technology category for eWEEK. Mr Rapoza's current technology focus is on all categories of emerging information technology though he continues to focus on core technology areas that include: content management systems, portal applications, Web publishing tools and security. Mr. Rapoza has coordinated several evaluations at enterprise organizations, including USA Today and The Prudential, to measure the capability of products and services under real-world conditions and against real-world criteria. Jim Rapoza's award-winning weekly column, Tech Directions, delves into all areas of technologies and the challenges of managing and deploying technology today.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×