Geek speak bridles information security
- 12 October, 2006 09:03
- Comments
Usability of security software is partly to blame for low protection levels in many computers, according to international security experts.
In a panel session at this year's Australian Unix Users Group (AUUG) conference in Melbourne yesterday, software security developers gave reasons why the IT industry is still at the mercy of so many problems.
University of Auckland computer scientist Peter Gutmann said many security standards were written 10 years ago and have mostly just been tweaked since then.
"A lot of the security stuff is designed by crypto geeks [and] because of a lack of usability, people can't apply them correctly," Gutmann said, adding usability is just as important as "having a bunch of crypto and let people figure it out from there".
Gutmann said the protocols were designed without usability and even if a user-friendly GUI could be put over it, it is unlikely the original developers would accept it.
"They would rather have 100 percent perfect software that's unusable than 99 percent perfect software that is usable," he said.
OpenBSD developer Ryan McBride, who works on packet filter and IPSec code, lashed out at intrusion detection systems, saying the technique has no way of detecting whether a virus is attacking a network.
"I do IDS work in a Fortune 50 company and it's a case of 'oh look, another box has a virus - go turn it off'," McBride said. "It's very hard to automate turning things off in security."
McBride said IDS isn't the place to solve the problem, but inside the software is.
University of NSW School of IT senior lecturer, Dr Lawrie Brown said when looking at modern software, part of the problem is the enormous body of un-safe software that people continue to use, which propagates vulnerabilites.
Brown said there is also a mindset within the general population that computers are relatively new and people are unaccustomed to the importance of information security.
German network security PhD student Tobias Eggendorfer seconded this by saying end users are not educated to deal with security threats.
"It will take 20 to 30 years to educate people about computer security," he said. "You wouldn't give your house key to someone, so why do the same with your password."
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
- ALM Buyers Guide: A Practical Guide to Choosing the Right Agile Tools for your Team
- Solid State Storage 101 - An introduction to Solid State Storage
- NetScaler 2048-bit SSL performance advantage
- Better Insights and Alignment with Business Intelligence and Scorecards
- Printer Usage and Cost Management Strategies for the Australian Mid-market, an Unrealised Opportunity
- iPhone 5 rumour rollup for the week ending February 10
- 3D mapping revives underwater city
- Academic challenges Turnbull over NBN satellite criticism
- What are you saying: Telstra’s customer service slowly improving, SA minister urging Facebook to overturn its photo ban
- In pictures: Capgemini opens new Canberra office
-
Maingear's six-core laptop has 1.8TB of SSD storage
-
After Megaupload shuts, BTJunkie follows
-
Windows Event Viewer phishing scam remains active
-
NeuroSky MindWave: Fun with Brainwaves
-
20 popular Ubuntu Linux apps you may want to try
-
Office 2007 All-In-One Desk Reference for Dummies
-
Office 2007 for Dummies
-
Computers for Seniors for Dummies, 2nd Edition
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Dummies®
-
Windows 7 for Seniors for Dummies®
-
MYOB Software for Dummies 6E Australian Edition
-
Windows 7 for Dummies® Dvd+book Bundle
-
Microsoft Office












Comments
Post new comment