You are here: silicon.com > Software > Security Strategy

Security Strategy

People 'too thick' to cope with viruses

Human error will keep bringing down security, say experts

By Michael Kanellos

Published: 25 February 2004 09:00 GMT

Although governments and companies appear to be making significant headway on many security problems, don't expect headaches like spam to disappear anytime soon, according to security experts.

Human error, combined with the increasing technical sophistication of malicious hackers, creates a situation in which security, ultimately, can never be perfect, security specialists on the cryptographer's panel at the RSA Conference said Tuesday.

Invariably, individuals will inadvertently open dangerous files or fall for cleverly deceptive spoofs. Even technically sophisticated users will make mistakes, according to Paul Kocher, president of Cryptography Research.

"We simply aren't smart enough as a species to handle this," Kocher said.

At the same time, solutions for solving some of these problems don't necessarily jibe with how individuals conduct themselves online, said Ronald Rivest, a professor of computer science at the Massachusetts Institute of Technology.

Some digital content protection schemes prevent a PC from opening up protected files. While that helps Hollywood, it represents a dramatic shift in the PC-owner relationship.

"You no longer have a PC that does what you tell it to do," Rivest said.

Spam presents another dilemma. Rivest, who has spoken out in the past against cryptography export restrictions, said he favors trying out a system in which the sender pays a fee to mail unsolicited messages. Then again, this system could be difficult to administer as increasing amounts of spam are sent from unwitting drone computers, pointed out Bruce Schneier, chief technology officer at Counterpane Internet Security.

Electronic voting also will likely create a host of controversies, Rivest said, because some of the systems already show potential flaws. In one election in Broward County, Florida, for instance, the winner won by 12 votes, but no votes were recorded for 137 people who actually went inside the booth to vote.

On the optimistic side, however, progress toward better security seems to be occurring. Adi Shamir, professor of the Weizmann Institute of Science in Israel, noted that in the past year, no major advanced cryptography system has been broken and no new ones have been introduced. Additionally, a Pentagon committee that oversees encryption has approved the use of the Advanced Encryption Standard (AES) for encrypting classified documents. The approval represents progress, because AES comes from Belgium and has been approved by international bodies.

"This was unthinkable years ago," said Whitfield Diffie, chief security officer at Sun Microsystems.

The panel also discussed the recent release of Windows code on the internet, but generally concluded that it didn't present that severe of a danger. National governments and other large organisations likely already possessed copies of the source code before the leak, Schneier pointed out. Kocher noted that one of the chief irritants of the leak is that legitimate Windows customers can't look at the code, but hackers can.

Shamir, however, countered that he wasn't going to look through tens of millions of lines of code. Not because it wouldn't reveal flaws, but because "it is boring."

Michael Kanellos writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
Development Project Officer - Contract - London - 6 Months

My client is looking for a Development Project Officer for a 6 month contract. You will have had experience of working within Housing Previously and ...

IT Support Officer

IT SUPPORT OFFICER - BRIXTON Initially 3 Months contract - 14.5 per hour The successful candidate will be working from our client's head office in ...

Information Governance Project Support Officer

An exciting opportunity has arisen in a prestigious London NHS Organisation for an Information Governance Project Support Officer.The Information ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: