Advertisement
Promo

Security threats Toolkit in association with http://ad.doubleclick.net/clk;214682528;14505427;f?http://uk.blackberry.com/ataglance/security/

Schneier: Security vendors exploiting user emotions

Angus Kidman ZDNet Australia

Published: 30 Jan 2008 12:02 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Linux.conf.au kicked off its main proceedings in Melbourne on Wednesday morning with a stark message from security guru Bruce Schneier: "When security companies give you cost justifications, they're complete bullshit."

Schneier, author of the books Applied Cryptography, Secrets and Lies and Beyond Fear and described by outgoing Linux Australia president Jonathan Oxer as "a walking security adviser on the entire human race", told a sold-out keynote audience that IT security planning is rarely effective because it fails to take into account the emotional considerations involved in security.

Most security products either address perceived gaps in security and provide an emotional sense of stability without actually doing much useful, or solve actual problems but don't impart the same sense of security, Schneier suggested.

"You can feel secure, even though you're not, and you can be secure even though you don't feel it," Schneier said.

"Making security trade-offs is something we do multiple times a day," Schneier noted. "You'd expect human beings would be really good at making these trade-offs but, fundamentally, we're hopelessly bad at it." The reason for that, he said, is that "we respond to the feeling of security rather than the reality".

Evolution means that pattern will be difficult to reverse, Schneier argued. "Our society is evolving faster than our species. Modern times are harder. Technology makes it harder and the media makes it harder."

"People make the trade-off based on the feeling of security, not the reality. The economic incentives are for companies to make people feel secure. That's where you are rewarded in the market," Schneier added.

Read this

Feature
Feature: Cracking open the cybercrime economy

Hacking for fun has evolved into hacking for profit, and created a business model that is nearly as sophisticated as that of legal software

Read more +

Drawing on George Akerlof's "lemons market" theory on the economics of information asymmetry, Schneier said: "In markets where the seller knows a lot more than the buyer, bad products drive out good products — and this is very much the case for security."

One notable problem, said Schneier, is the return-on-investment calculations for security software, which often draw on rare and devastating events to justify their cost, an approach which renders basic mathematics of little use.

"In IT, there isn't a lot of data. This is one of the problems we have. You have to rely on emotion because we don't have the data. It's very hard to evaluate non-functional requirements," Schneier said.

Understanding of fundamental security principles also needs to dramatically improve, Schneier said.

"We know very little about software security. We can't even prove a program terminates, let alone that it's secure. We don't have a rigorous security methodology. It's going to be a long time before it can be applied to programs and systems and anything resembling actual commercial size."

Credit: Schneier: Why rubbish security products win out from ZDNet Australia

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
9 out of 9 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:



Video icon

Video

Sentry Posts Blog

Behind the Scenes: Next Gen Mobile Tec...

Behind the Scenes: Next Gen Mobile Technology Author: Eric Everson, Founder MyMobiSafe.com With infrastructure speeds continually improving at the network level of the world’s leading... More

Post a comment

Nasa hacker petition presented to Numb...

Sting's wife Trudie Styler and Janis Sharp have presented a petition to Number 10 calling for Nasa hacker Gary McKinnon not to be extradited to the US. Styler, and Sharp, who is... More

Post a comment

UK to appoint cyber-sec tsar?

The UK is to appoint a cyber security tsar along the lines of the US, according to a story in the Telegraph this morning. The story is similar to one that appeared in the Guardian... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters