ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Schneier: Security vendors exploiting user emotions

Angus Kidman ZDNet Australia

Published: 30 Jan 2008 12:02 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Linux.conf.au kicked off its main proceedings in Melbourne on Wednesday morning with a stark message from security guru Bruce Schneier: "When security companies give you cost justifications, they're complete bullshit."

Schneier, author of the books Applied Cryptography, Secrets and Lies and Beyond Fear and described by outgoing Linux Australia president Jonathan Oxer as "a walking security adviser on the entire human race", told a sold-out keynote audience that IT security planning is rarely effective because it fails to take into account the emotional considerations involved in security.

Most security products either address perceived gaps in security and provide an emotional sense of stability without actually doing much useful, or solve actual problems but don't impart the same sense of security, Schneier suggested.

"You can feel secure, even though you're not, and you can be secure even though you don't feel it," Schneier said.

"Making security trade-offs is something we do multiple times a day," Schneier noted. "You'd expect human beings would be really good at making these trade-offs but, fundamentally, we're hopelessly bad at it." The reason for that, he said, is that "we respond to the feeling of security rather than the reality".

Evolution means that pattern will be difficult to reverse, Schneier argued. "Our society is evolving faster than our species. Modern times are harder. Technology makes it harder and the media makes it harder."

"People make the trade-off based on the feeling of security, not the reality. The economic incentives are for companies to make people feel secure. That's where you are rewarded in the market," Schneier added.

Read this

Feature
Feature: Cracking open the cybercrime economy

Hacking for fun has evolved into hacking for profit, and created a business model that is nearly as sophisticated as that of legal software

Read more +

Drawing on George Akerlof's "lemons market" theory on the economics of information asymmetry, Schneier said: "In markets where the seller knows a lot more than the buyer, bad products drive out good products — and this is very much the case for security."

One notable problem, said Schneier, is the return-on-investment calculations for security software, which often draw on rare and devastating events to justify their cost, an approach which renders basic mathematics of little use.

"In IT, there isn't a lot of data. This is one of the problems we have. You have to rely on emotion because we don't have the data. It's very hard to evaluate non-functional requirements," Schneier said.

Understanding of fundamental security principles also needs to dramatically improve, Schneier said.

"We know very little about software security. We can't even prove a program terminates, let alone that it's secure. We don't have a rigorous security methodology. It's going to be a long time before it can be applied to programs and systems and anything resembling actual commercial size."

Credit: Schneier: Why rubbish security products win out from ZDNet Australia

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
9 out of 9 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

Trade Analysts required for Major Oil Company, London

Experience working on the trade floor and liasing with traders on a daily basis is sure step to take you there. Our client seeks Trade Control ...

Junior Level Desktop Support (Trade Support,Market Data,AD)HEDGE FUND

The ideal candidate MUST be educated to degree level with some current trade floor experience, market data & blackberry support. Prestigious Top 10 ...

Trade Floor Support Analyst - Investment Bank £55k

Our client, a top Investment Bank, based in the City of London, is currently looking for a Trade Floor Support Analyst. The responsibilities are to: ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment