Ads by TechWords

See your link here
Receive the latest technology news and information.
Data Management
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Weak security taints directory

Fake listings, lack of vetting undermine UDDI

June 18, 2001 12:00 PM ET

Computerworld - A major industry effort to build an online directory of Web services for business is riddled with embarrassing security problems that have marred its arrival.


Last month's launch of the Universal Description, Discovery and Integration directory, a Yellow Pages-style directory that lets businesses register their Internet services and capabilities online, was intended to drive support for Web services (see story). But lax security by UDDI founders IBM and Microsoft Corp. has permitted the Web-based directory to be populated with fake firms, false links and uninformed participants.


For example, "Loud Speakers Inc." is registered as a Mountain View, Calif.-based firm run by John McLoud, whose public speakers talk at a level higher than 100 decibels. The UDDI also describes Loud Speaker's Web service as juju beads for "warding off evil spirits." The company isn't listed with directory assistance and can't be found on the Web.


As for bad links, the UDDI listing for Oracle Corp. links to a pornography site, not a Web service.


"Microsoft is aware that security is an issue," said Darryl Plummer, an analyst at Stamford, Conn.-based Gartner Inc. "As you open things up, you open up the door for security holes. They're trying to come up to speed in a public forum, and if large controls were in place, it wouldn't take off."


Microsoft officials said controls for vetting companies that register in the UDDI directory would be discussed at a private conference for the registry's adviser group in Atlanta this week.


But beyond the challenge of vetting registrants, the sponsors of the UDDI directory also appear to be facing another problem: uninformed directory members.


Markle Stuckey Hardesty & Bott is listed in the UDDI directory. But David Hardesty, vice president of the Larkspur, Calif.-based e-commerce accounting firm, said he has no idea what the directory is and has no plans to introduce Web services at his company.


"I have no recollection of registering," said Hardesty. "We haven't used it, and we don't know anything about it, but that's not to say that we didn't sign up for it. There are lots of things out there on the Web, but you just can't remember everything."


Bob Gill, owner of Shrimp Landing, a seafood wholesaler in Crystal River, Fla., said he agreed to register after responding to an e-mail solicitation from IBM.


But Gill said he doesn't see himself using or offering Web services from the company's one-page Web site.


"I'm sticking my neck into an area for which I know nothing about," said Gill. "First, I need to get my site up and running. Then I'll think about it."



Jump to comments

Data Mining

Additional Resources

Microsoft
Here are some of the key reasons why you would want to run Unified Access Gateway with DirectAccess.
Microsoft
Review how one energy firm tightened protection and simplified IT work using business-ready security solutions.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

White Papers & Webcasts

Data Grids & SOA
Get this paper now!  

The Workday User Experience Video
Watch Workday's Creative Director, Scott Lietzke, discuss the business-centered design philosophy at Workday.

Business Process Framework Demo
Learn about Configurable Business Processes and Calculated Fields. Watch Now!

Manager Experience Demo
Go beyond self-service solutions to perform more effectively. Watch Now.


IT Jobs

 

SAS Information Management Kit

SAS is the leader in business intelligence and analytical software and services. Only SAS offers leading data integration, storage, analytics and business intelligence applications within a comprehensive enterprise intelligence platform. SAS gives 97 of the top 100 companies in the 2007 Fortune 500 THE POWER TO KNOW®.

Webcast: The Information Management Roadmap
Imagine high-quality data, cleansed, analyzed and delivered throughout your organization. Join Computerworld, IT visionary Thornton May and a panel of experts to learn how SAS® can help you make it happen.

View this webcast 
Research Report: Information Management Initiatives at Midsize and Large Organizations
See the top-line results of this Computerworld sponsored survey to see how IT and business leaders are handling information management implementation.

Download this report 
White Paper: Information Management: Better Information for Winning Decisions.
This white paper explains how the SAS Information Evolution Model aids companies in assessing how they use this information to make strategic decisions and drive business.

Download this white paper