While AJAX (Asynchronous JavaScript and XML) may have issues with security and performance, Zimbra still sees AJAX as the best way to deliver experiences on the Web and has based its open source Web 2.0 platform on 200,000 lines of JavaScript, a company executive said Monday.
At the Web Builder 2.0 conference in Las Vegas, Zimbra president and CTO Scott Dietzen, former CTO of BEA Systems, emphasized a variety of AJAX and Web 2.0 technologies for developers and users, including the extension of AJAX to offline usage.
Despite its problems, Dietzen said he favors AJAX over other technologies such as Flash when it comes to the Web.
"There's no other way to deliver a richly interactive experience on the Web," he said. "If you want the Web look and feel and the ability to mash up all sorts of other Web technologies, I think AJAX is the best fit."
Zimbra, which was acquired by Yahoo earlier this year for $350 million, offers collaboration and messaging software.
Dietzen did cite AJAX security issues such as cross-site scripting attacks, in which user data can get interpreted in the browser, creating a breach. Also noted as a security concern was use of source code in the browser.
"The goal for rich Internet applications at least ought to be to deliver the same level of security that we've delivered for Web applications because to deliver less undermines user confidence in various ways," he said. This is a goal that is close to being achieved, Dietzen said.
Blocking execution of user JavaScript inside of the application is important to combat server-side scripting attacks, according to Dietzen. Obfuscation and minimization technologies to remove white space can be used as security measures, he said. On the positive side, there is no caching of user data on the desktop with AJAX. Dietzen also advised that sensitive code not be put in the browser.
Browsers, meanwhile, also present challenges. They render the same HTML differently and were not designed for the load presented by AJAX; browsers have memory leaks and performance gaps, Dietzen said. But browsers are getting better, Dietzen said.
"Safari 3 is dramatically better," he said. Internet Explorer 7 offers a two to four times improvement in JavaScript execution for Zimbra over Internet Explorer 6, Dietzen said.
Toolkits also have been a problem but that, too, has been getting better. Toolkits now are available from organizations such as Eclipse, Adobe, and Microsoft. "I'm happy to say no more Zimbra developers are using text editors or vi to craft their JavaScript," said Dietzen.
Offline AJAX usage is a "hot topic," Dietzen said. Zimbra now can be used offline, he said.
"The answer for occasionally connected apps is to provide a cache on the client side that allows the application to interact locally with a data set, and synchronize over the network when the network is available," said Dietzen.
Offline AJAX systems can be developed by using a set of caching APIs in JavaScript that enable this. These are accessible via offerings such as Google Gears and Dojo offline toolkit.
This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.
Download now »Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.
Download now »
The emergence of WLANs has created a new breed of security threats to enterprise networks.
Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation
Effectively address data protection challenges, implementing solutions that help store and protect businesscritical data while cutting costs and improving efficiency and reliability.
Download now »
Sign up to receive InfoWorld Resource Alerts
