ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

Infosec 2007

Schneier questions need for security industry

Will Sturgeon silicon.com

Published: 26 Apr 2007 11:48 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Outspoken author and security guru Bruce Schneier has questioned the very existence of the security industry, suggesting it merely indicates the willingness of other technology companies to ship insecure software and hardware.

Speaking at the Infosecurity show at London Olympia this week — a leading trade show for the security industry — Schneier said: "The fact this show even exists is a problem. You should not have to come to this show ever. "

"We shouldn't have to come and find a company to secure our email. Email should already be secure. We shouldn't have to buy from somebody to secure our network or servers. Our networks and servers should already be secure," Schneier continued.

Read this

Leader
Leader: Security through responsibility

Security providers are in rude health, unlike security itself. The industry must make itself more accountable if it is to make real progress for its customers…

Read more +

Schneier, chief technology officer at Counterpane, said his own company was bought by BT last year because the network realised the need for security to be a part of any service, not an add-on at additional cost and inconvenience to the user.

His words echoed those of Lord Broers, chair of the House of Lords science and technology committee, who suggested every company, from operating system and application vendors to ISPs, needs to take greater responsibility for the security of end users.

"Security is a small but important piece of the bigger picture," Schneier said. He added that consumers shouldn't accept any product that is inherently insecure.

However, Graham Cluley, senior technology consultant at Sophos, suggested Schneier's dream may be a long way from reality. "Why didn't everybody think about this sooner?" said Cluley. "It would be great."

He added: "It would be great if robberies didn't happen and if road accidents didn't happen and if I didn't stub my toe but what you have to realise is that software developers are human and humans make mistakes.

"I can't imagine there ever being a 100 percent secure operating system, because a vital component of programming that operating system is human."

Jon Collins, service director at analyst house Freeform Dynamics, expressed his own doubts about the value of the security industry but said it will always be fed by dual forces of end-user error and the shipping of insecure products.

"I always used to think the security industry existed to make people scared and then sell them something to protect them from what they were afraid of. But now I think it exists because of what people are prepared to buy," he said, adding that security investment tends to be reactive to a problem a company has already suffered — making security a "fire extinguisher industry".

But Collins added that it is not true to suggest that user reaction is always due to inherently insecure software or hardware.

"Even if everything was secured, the end user would still find a way to configure it wrong or install it wrong or enable the wrong privileges and permissions," he said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

C# Developer - Top Financial Software House - Cross Asset Products

A leading software house is looking for a strong C# development profile to develop and design their real-time, electronic trading and market data ...

Trading Systems Analyst, Energy Trading, Trading House, City

A leading energy trading house is currently looking for two systems analysts to join their expanding team. This trading house has recently undergone ...

Human Resources Manager - NHS - North West - Contract

Leading NHS organisation now has a fantastic opportunity for a NHS Senior Human Resources Manager. The NHS Senior Human Resources Manager will join a ...

Discussions

319762 319762

Eve of Distraction

Saturday 26 July 2008, 4:37 AM

1 comment

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal