Advertisement
Promo

Security threats Toolkit in association with http://ad.doubleclick.net/clk;214682528;14505427;f?http://uk.blackberry.com/ataglance/security/

Presidential advisor slams software security

Munir Kotadia ZDNet.co.uk

Published: 26 Feb 2004 15:55 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

An advisor to the US' Homeland Security Council has lashed out at software developers, arguing their failure to deliver secure code is responsible for most security threats.

Retired lieutenant general John Gordon, presidential assistant and advisor to the Homeland Security Council, used his keynote address at the RSA Security conference in San Francisco on Wednesday to question how much effort developers are putting into ensuring their code is watertight. "This is a problem for every company that writes software. It cannot be beyond our ability to learn how to write and distribute software with much higher standards of care and much reduced rate of errors and much reduced set of vulnerabilities," he said.

Gordon's keynote followed a day after that of Microsoft chairman Bill Gates.

According to Gordon, if developers could reduce the error and vulnerability rate by a factor of 10, it would "probably eliminate something like 90 percent of the current security threats and vulnerabilities.

"Once we start writing and deploying secure code, every other problem in cybersecurity is fundamentally more manageable as we close off possible points of attack," he said.

Gordon also criticised wireless network manufacturers for making encryption too difficult to deploy, even for "technically competent" users. He made the comments after explaining that he had spent a long weekend trying to set up a Wi-Fi network at his house.

"One manufacturer got to invest an entire man-day of tech support and about eight hours of telephone charges. At the end of the day, I still had not accomplished a successful installation," said Gordon, who eventually managed to get the network running by "taking some steps that were not in the documentation".

However, he said the documentation didn't make it clear how to secure his network: "The industry needs to make it easy for users like me -- who are reasonably technically competent -- to employ solid security features and not make it so tempting to simply ignore security."

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
88 out of 184 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

Behind the Scenes: Next Gen Mobile Tec...

Behind the Scenes: Next Gen Mobile Technology Author: Eric Everson, Founder MyMobiSafe.com With infrastructure speeds continually improving at the network level of the world’s leading... More

Post a comment

Nasa hacker petition presented to Numb...

Sting's wife Trudie Styler and Janis Sharp have presented a petition to Number 10 calling for Nasa hacker Gary McKinnon not to be extradited to the US. Styler, and Sharp, who is... More

Post a comment

UK to appoint cyber-sec tsar?

The UK is to appoint a cyber security tsar along the lines of the US, according to a story in the Telegraph this morning. The story is similar to one that appeared in the Guardian... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters