Sunday, December 5, 2010

The forest and the trees



According to the ISC^2 under the information security governance and risk management section of the common body of knowledge there exist a number of rules regarding the ISC^2 code of ethicsi;

The no free lunch rule” - “Assume that all information and property belongs to someone.”

ComScore states that e-commerce spending neared 34 billion dollars in the first quarter of 2010ii.

Of the 256,000,000 websites on-lineiii; as of 2007 there were 20,000,000 using php this is of 102,400,000 total domains at the timeiv. If we assume these trends have remained constant then we may extrapolate that around 35% to 50% of all web-sites on-line use php scriptingv.

The TIOBE index for 2010 states that PHP falls just behind C/C++, and JAVA in popularityvi.

Most companies which engage programmers to develop applications for them retain intellectual property rightsvii. These rights and applications are the tools used to extract value from eCommerce.

Web development by it's very nature is open; the main issue that business managers have with regards to web facing presence is that they expose the company to a degree of risk; these include the risk of theft of IPviii. Google had it's Intellectual property removed by force and order of the chinese government due to a politicians disdain for his on line presence. Since Google net worth is approaching 5 billion, we can see that this theft of IP would be the equivalent of stealing a bakers oven, or a delivery companies planes, trains and vans.

Legal considerations aside; the future of web development is open, but in a validated escaped vetted and verified manner. As applications become more dependent on web-based technologies; such as the games in facebook, or how salesforce.com can pull contact information from linked in; the sites that work with one another use the number of users as a method to apply a metric from which to derive economic value.

People often quote that facebook is worth x billion of dollars based on the data the web-site retains; however real asset valuation is usually based on revenue plus operations and management plus cash in hand and holdings. Far too often do we as investors assign value to worthless ideas. Facebook is based on enabling a distributed community of people to tag meta data within digital photos. This idea is patented formally and coded on the platform that is facebook.

The future of web development will have greater interconnectivity, however these levels will be offset by the needs for the enforcement of privacy legislation and both local and non-local security interests.

The nature of how future web-sites will communicate may involve active security testing as part of the web-sites operations and api development; DNS based secure validation may also be required for all domains, further to this we will also see a rise in privacy violations made by companies since they are often neither enforced nor punished legally for doing so.

I see a forest of many brilliant trees with fireproof bark whose branches only cover certain valuable areas; the mycelium of this forest is ironclad and paid for.

Future web-sites will be service level based connections that are agreed upon by the various data holders; such as facebook, google and the like, and they will probably be fortified by in-line detection of any and all valid code and transactions, mired in legal requirements and legislation and audited by many security personnel.

As the internet grows and adoption continues to rise in global adoption; the future of website development is very open, the nature of the back end of websites is becoming far more closed and restricted. This is to protect the investment of both human and real capitol in the development of these most brilliant tools.


iHarold F. Tipton (CRC Press, 2010) Offical ISC Guide to the CISSP CBK 2nd ed. P.495
iiN.A. (comScore, Marketing Charts) Q1 E-commerce spending rises 10% [Online] World Wide Web, Available from: http://www.marketingcharts.com/direct/q1-e-commerce-spending-rises-10-12982/?utm_campaign=rssfeed&utm_source=mc&utm_medium=textlink (Accessed on December 5th 2010)
iiiN.A. (Netcraft ) Web Server Survey [Online] World Wide Web, Available from: http://news.netcraft.com/archives/category/web-server-survey/ (Accessed on December 5th 2010)
ivN.A. (php.net) Usage Stats [Online] World Wide Web, Available from: http://php.net/usage.php (Accessed on December 5th 2010)
vSeguy, Damien (nexen.net, 2008) All statistics related to PHP [Online] World Wide Web, Available from: http://www.nexen.net/chiffres_cles/phpversion/ (Accessed on December 5th 2010)
viN.A. (TIOBE Software) TIOBE Programming Index for November 2010
viiNicholson, Andrew (FindLaw, Austrialia) Without Employment Contracts employeers risk losing IP [Online] World Wide Web, Available from: http://www.findlaw.com.au/articles/2269/without-employment-contracts---employers-risk-losi.aspx (Accessed on December 5th 2010)
viiiThomsan, Ian (V3.co.uk, November 29th 2010) Wikileaks Cable showed that China politburo oreded Google Hack [Online] World Wide Web, Available from: http://www.v3.co.uk/v3/news/2273507/wikileaks-google-china-cables (Accessed on December 5th 2010)

No comments:

Post a Comment