Candidate OWASP Top 10 Client-Side Security Risks posted

79 views
Skip to first unread message

Dave Wichers

unread,
Jun 26, 2022, 4:12:53 PM6/26/22
to Top 10 Client Side Security Risks
All,

I know this mailing list is really small :-), but hopefully it will start growing soon!  Anyway, I just updated the project home page: https://owasp.org/www-project-top-10-client-side-security-risks/, with the list of 10 candidates for this Top 10.

Please forward info about this to anyone you know interested in this topic and encourage them to join this mailing list and provide feedback. Now we need to get the word out on this work!

Thanks everyone.

-Dave

Jim Manico

unread,
Jun 30, 2022, 5:08:41 PM6/30/22
to Dave Wichers, Top 10 Client Side Security Risks

Dave Wichers

unread,
Jun 30, 2022, 7:31:46 PM6/30/22
to Jim Manico, Top 10 Client Side Security Risks
Thanks Jim!

> On Jun 30, 2022, at 5:08 PM, Jim Manico <jim.m...@owasp.org> wrote:
>
> Here we go!

Jim Manico

unread,
Jun 30, 2022, 9:11:02 PM6/30/22
to Dave Wichers, Top 10 Client Side Security Risks
Absolutely, great project!

--
Jim Manico
@Manicode
(808) 652-3805

> On Jun 30, 2022, at 1:31 PM, Dave Wichers <dave.w...@owasp.org> wrote:
>
> Thanks Jim!

Jim Weiler

unread,
Aug 12, 2022, 6:46:34 PM8/12/22
to Top 10 Client Side Security Risks, Jim Manico, Top 10 Client Side Security Risks, Dave Wichers
In the second paragraph -  Mobile apps are frequently the client-side of a web app, where the server-side of the web app provides REST services to the mobile app . I think the client side of an app is either web  (browser) or native mobile app. And the server side isn't always REST. So I would delete the word 'web' and say  Mobile apps are frequently the client-side of an app, where the server-side of the app provides API services to the mobile app 

Dave Wichers

unread,
Aug 12, 2022, 6:52:13 PM8/12/22
to Jim Weiler, Top 10 Client Side Security Risks, Jim Manico
Sounds reasonable to me.

-Dave

Ivan Tsarynny

unread,
Aug 12, 2022, 10:27:05 PM8/12/22
to Dave Wichers, Jim Weiler, Top 10 Client Side Security Risks, Jim Manico
Thanks Jim. 
That makes sense. I will get to it on Sunday. 
Thanks
Ivan 

On Aug 12, 2022, at 6:52 PM, Dave Wichers <dave.w...@owasp.org> wrote:



Jim Weiler

unread,
Nov 2, 2022, 6:09:41 PM11/2/22
to Top 10 Client Side Security Risks, ivan tsarynny, Jim Weiler, Top 10 Client Side Security Risks, Jim Manico, Dave Wichers
Hi Folks,
I'm going to  retire Dec. 31,  so naturally I want to spend more time on OWASP stuff. Planning to add remediations next year, if we are still planning to add them. Any other tasks I can plan to do?
Jim

Lavakumar Kuppan

unread,
Nov 3, 2022, 1:54:06 PM11/3/22
to Jim Weiler, top 10 client side security risks, ivan tsarynny, jim manico, dave wichers
Hello Jim,

Best wishes for your retirement.

I vote for adding remediations.

Ideally I would want us to get to a point where we have content parity with the OWASP Top 10.
Each of the OWASP Top 10 items have a separate page dedicated to it with overview, description, remediation and examples.

Would love to contribute if you need an extra hand in your remediation work.

Thanks,
Lava



---- On Thu, 03 Nov 2022 03:39:41 +0530 Jim Weiler <jim.w...@owasp.org> wrote ---

--
You received this message because you are subscribed to the Google Groups "Top 10 Client Side Security Risks" group.
To unsubscribe from this group and stop receiving emails from it, send an email to top10-client-side-secu...@owasp.org.


Dave Wichers

unread,
Nov 3, 2022, 1:57:50 PM11/3/22
to Lavakumar Kuppan, Jim Weiler, top 10 client side security risks, ivan tsarynny, jim manico
We definitely need the help Lava. Ivan just needs to organize the next steps and getting everyone marching orders to get the project moving forward again.

Ivan??

-Dave

ivan tsarynny

unread,
Nov 4, 2022, 3:51:24 PM11/4/22
to Dave Wichers, Lavakumar Kuppan, Jim Weiler, top 10 client side security risks, jim manico
Lava, thanks! 
That’s a great recommendation. Jim W., let’s get it updated and moved to the next stage before your retirement! Hope you can still be available after December 31st.

The most updated version is here. Let’s meet this coming week to get going. 
How is 9am et on November 8th, 9th, or 10th?
thanks
Ivan 

ivan tsarynny

unread,
Nov 7, 2022, 4:36:15 PM11/7/22
to Dave Wichers, Lavakumar Kuppan, Jim Weiler, top 10 client side security risks, jim manico
Hi Lava. Jim W. and Jim M. Are you available at any of these times?
Thanks 
Ivan 

Lavakumar Kuppan

unread,
Nov 8, 2022, 2:12:49 AM11/8/22
to ivan tsarynny, dave wichers, jim weiler, top 10 client side security risks, jim manico
Hi Ivan,

I am available on the 9th and 10th at 9AM ET.

Thanks,
Lava



---- On Tue, 08 Nov 2022 03:06:12 +0530 ivan tsarynny <ivan.t...@owasp.org> wrote ---

Jim Manico

unread,
Nov 8, 2022, 9:08:09 AM11/8/22
to Lavakumar Kuppan, ivan tsarynny, dave wichers, jim weiler, top 10 client side security risks
I am teaching all week but am free next week.


--
Jim Manico
@Manicode

On Nov 7, 2022, at 11:12 PM, Lavakumar Kuppan <la...@sboxr.com> wrote:



Lavakumar Kuppan

unread,
Nov 8, 2022, 10:24:25 AM11/8/22
to Weiler, James, jim manico, ivan tsarynny, dave wichers, jim weiler, top 10 client side security risks

I will be at Blackhat MEA so next week doesn't work for me.  
I can do this between 21st Nov - 3rd Dec.
If others can share their available dates too then we can pick a date with mutual overlap. 



---- On Tue, 08 Nov 2022 20:17:23 +0530 Weiler, James <James....@marriott.com> wrote ---

MARRIOTT CONFIDENTIAL AND PROPRIETARY INFORMATION


I’m available on the 10th at 9 am. There’s no hurry to do things before my retirement – I’m busier at work wrapping things up. I will have lots of time for OWASP after retirement.

Next week is fine too.

 

Jim Weiler

Director, Integration Management – Application Security

Global Information Security

239 Old Jail Lane, Barnstable MA. 02630

781-654-6048  (M)


 

From: Jim Manico <jim.m...@owasp.org>
Sent: Tuesday, November 8, 2022 9:08 AM
To: Lavakumar Kuppan <la...@sboxr.com>
Cc: ivan tsarynny <ivan.t...@owasp.org>; dave wichers <dave.w...@owasp.org>; jim weiler <jim.w...@owasp.org>; top 10 client side security risks <top10-client-side-...@owasp.org>
Subject: Re: Candidate OWASP Top 10 Client-Side Security Risks posted

 

This message is from an EXTERNAL SENDER - be CAUTIOUS, particularly with links and attachments


MARRIOTT CONFIDENTIAL AND PROPRIETARY INFORMATION



ivan tsarynny

unread,
Nov 8, 2022, 1:55:01 PM11/8/22
to Jim Manico, Lavakumar Kuppan, dave wichers, jim weiler, top 10 client side security risks
Looks like Nov 10th @9am et works for most of the team. I will send meeting invasion shortly. 

Jim M., how is Nov 16th at 9am et for you?

Lavakumar Kuppan

unread,
Nov 9, 2022, 8:16:01 AM11/9/22
to ivan tsarynny, jim manico, dave wichers, jim weiler, top 10 client side security risks
Thank you Ivan!



---- On Wed, 09 Nov 2022 00:24:58 +0530 ivan tsarynny <ivan.t...@owasp.org> wrote ---
Reply all
Reply to author
Forward
0 new messages