Advertisement
Promo

Network management Toolkit in association with http://ad.doubleclick.net/clk;217618582;14453422;e?http://www.citrix.com/lang/English/lp/lp_1688615.asp

People, not passwords, are the key to security

Leader ZDNet.co.uk

Published: 01 Nov 2004 12:44 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Students of the human condition will find little to surprise them in Gartner's latest report. It says that social engineering – duping people – will be the biggest security risk for companies and individuals over the next decade. In other words, there's no point in setting up a biometric access, triple-DES encryption, policy managed and physically secure server if the users can be persuaded to misbehave.

Confidence tricksters, like the poor, will be with us always. Mankind's earliest myths talk of deception and lies, and we have yet to break the habit. As the siege of Troy showed, when the physical defences get good enough, humans become the weakest link – and while we can always re-engineer our machinery, we are stuck with people.

All of which teaches us a lesson that IT would much rather ignore: people should come first, programmers second. We see it in email systems that can embed live data objects in messages because that is cool and easy to program, but do not have proper message threading. We see it in open source, where usability is harder to come by than a copy of the GPL with Bill Gates' signature on the bottom.

We especially see it in online security, where the user is supposed to remember all manner of things – tiny yellow padlocks, checking URLs for https://, and a different password for every site – and to be responsible for filtering safe options from heavily disguised con jobs. People cannot manage security well in real life, so why do security designers assume otherwise in the virtual world where by definition nothing is quite what it seems?

Computer security is designed by engineers and sold by marketing departments. Neither group is known for its deep insights into human behaviour, although both have considerable self-confidence that their way is the right way if only the rest of the world would fall into line. Well, that ain't going to happen – something the open source community is discovering now that most of its users aren't also developers.

There are two groups of people who must get much more involved in IT design, security and otherwise, now that the days of the expert user are irretrievably past. Humanities experts are one group – anthropologists, sociologists, psychologists, graphics designers, even dramatists – while the other is the user base itself.

Look at the Bugtraq entries for any major open source effort, and more than 90 percent of the problems reported are feature-based. The problems ordinary people have with software are overwhelmingly usability related – but the reporting mechanisms that reach designers might as well be written in Sanskrit.

There are no forums for the feedback of ordinary users to design teams. There are no wide-scale usability studies by security companies, let alone ones that use the Internet to reach out to the very people most at threat. Saying that 'people are the problem' is getting the issue precisely wrong: people - - not data, not security, not network management -- are the very core of IT's purpose and reason to exist.

It is sad that after more than fifty years of commercial computing this lesson still has to be learned. It has never been more pressing.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
30 out of 55 people found this useful


Full Talkback thread

1 comment

  1. Whatever the rights on this issue it does show a v... Roger Jarvis

Company/Topic Alerts

Create a new alert from the list below:






Related Citrix Resources

Achieving the lowest server virtualization TCO

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Achieving the lowest server virtualization Total Cost of Ownership

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Citrix XenDesktop: The Best Desktop Delivery System For Today's Demanding Business Needs

Whether you're considering your first virtual desktop solution or trying to salvage an existing...

Desktop Virtualization: A buyer's checklist

Desktop virtualization should do more than just move desktop management to the datacenter—its real...

Five reasons why you need Citrix Essentials for Hyper-V now

This paper explores common challenges associated with server virtualization deployments and the...

See All White Papers

Video icon

Video

On The Road Blog

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Ubuntu 9.10 (karmic Koala) on Netbooks...

In Part 1 of this series, I looked at the "standard" Ubuntu distribution, and found that with some adjustments, it could be made into what I considered to be a fairly nicely usable... More

Post a comment

Ubuntu 9.10 (karmic Koala) on Netbooks...

In Part 1 I discussed some generalities about the new Ubuntu 9.10 distribution, and some issues related to using it on netbook computers. Now it is time to move on to the Ubuntu Netbook... More

3 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters