ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Online business Toolkit

Internet will never be secure, says Schneier

Wendy McAuliffe ZDNet.co.uk

Published: 26 Sep 2001 17:27 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The complexity of the Internet is increasing more rapidly than our ability to secure it, according to Internet security expert Bruce Schneier.

At the opening of the annual Information Security Solutions Europe (ISSE) conference in London on Wednesday, Schneier, who is chief technology officer of Counterpane Internet Security, claimed that the problem of Internet security will never be resolved.

"Traditionally, Internet security has been thought of as a technology issue, based on the notion that you can build products to plug the holes," said Schneier. "But we are losing the battle with computer security, as we are building new products, but every year gets actively worse."

Software is getting increasingly complex, creating myriad vulnerabilities for virus writers to exploit. This was demonstrated with the recent outbreak of two major computer viruses -- Code Red and its hybrid version Nimda -- which attacked the same buffer-overflow vulnerability in Microsoft's IIS software. But as David Perry, security expert at Trend Micro, highlights, IIS is "a flash in the pan", and will soon be supplanted by a more popular application for hackers to target.

"The Internet is the most complex machine that man has ever built, so there will be accidents," said Schneier. "We are one big network, and things that affect one affect many."

The terrorist attacks on New York and Washington earlier this month rewrote the history books on information security. The atrocities have been branded as the world's biggest ever intelligence failure, raising a huge question mark over the future of security in cyberspace. Knee-jerk reactions by federal agencies in the US have called for an increase in electronic surveillance, but according to Schneier, the solution doesn't lie in stepping up technological intervention.

"We've spent a lot of time over-investing in data collection and electronic surveillance, but there is not enough human intelligence and interpretation," said Schneier. "Looking at how quickly the FBI pieced together the last month of the terrorists' lives, they have enough data, but they didn't know how to use it."

According to Schneier, human intervention is critical in the fight against Internet security breaches. "Hackers collaborate, but at the moment defenders are isolating themselves," he said. This is made worse by the current stigma attached to cyberattacks -- companies are still reluctant to report hacker attacks owing to the damage this could have upon their brands. But, he said, this will change: "As society becomes more lawful, people will be more willing to go public on cyberattacks," said Schneier.

See the Viruses and Hacking News Section for the latest headlines.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
46 out of 90 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:












Sentry Posts Blog

Nasa and the virus

Yesterday the BBC ran a story about a computer virus making it into orbit, which I read with incredulity. OK, it's a nice silly season story on the surface, but what really got me was... More

3 comments

Customer data found on eBay server hig...

The recent news about customer details being retrieved from a server sold on eBay is yet another story about the sorry state of information security in the electronic age (see: http://news.zdnet.co.uk/...m).... More

Post a comment

Does it matter if you are an aardvark...

In spam terms, apparently it does. According to Cambridge University security expert Richard Clayton, if your email address is aardvark at animal.net, you are more likely to receive... More

5 comments