OK - but from a CIO's perspective, any security risk is too much both from the bad guys getting in and creating mischief, and proprietary data getting out (in my business, more the latter). Until innovations stabilize, I would think that every CIO will choose isolation. Unfortunately, once there it's hard to get them back out. How do you get the CIOs to either wait or to adopt temporary solutions?
Absolutely. Part of the problem is that everyone is being rational here! For CIOs I can understand the desire to bolt everything down. But I guess I'd say that bolting down too much can be like stripping a screw... employees will end up creating their own shadow IT if the official systems are too locked down. I'd ask CIOs to be willing to participate in some of the "digital nervous system" apps that we're developing (we're = Oxford/Harvard) to allow PCs to anonymously broadcast their basic vital signs (not the company documents), especially because then mainstream Internet users could ask the system things like, "How many expert/corporate machines have this software installed, vs. the AOL-types?" (apologies to AOL types)
You write glowingly of the open, collaborative process used to create Wikipedia. How can a process like that can be used to solve today's worst cybersecurity problems, which are criminal in nature?
I'm eager to see us develop the kinds of technical tools that Wikipedia has -- think quick revert -- so that harmful stuff isn't a catastrophe. And tools that let people collaborate to give early warning of bad or unfamiliar code. Right now surfing the Web is designed to be an autistic experience.
Do you use an iPhone, Blackberry or other PDA? How do you square that with your views of how tethered Internet appliances are hampering innovation on the Internet?
I actually don't use any of those devices -- I find that email is fun when it comes in, but a burden once it's stale, which is in about five seconds. So I like to deal with email from a PC, when I'm devoted to truly processing it. But I'm not too doctrinaire about it -- I don't think the iPhone is evil, just that (1) it and platforms like it may well crowd out the PC and (2) if that happens, we'll lose much of the ability to innovate that we've enjoyed for the past thirty years. And we'll gain new vectors of government/regulatory surveillance and control. Facebook can be told to kill Scrabulous in a way that Bill Gates was never told to kill Grokster or Bittorrent.
Are there many open/closed mixed products and are we heading back to the "old days" in some sense?
I think the iPhone w/SDK is a good example of a mixed product -- a "contingently generative" technology. I worry it's the worst of both worlds rather than the best - and I see Facebook and Google apps the same way. I like 'em both, but they both reserve the right to kill any app at any time - so it's the old days of appliances, but still the new days of networked: with the vendor having a privileged role in reprogramming the users' experiences.
One of the big security risks we see today are not necessarily the open net but these little high-capacity memory drives that can contain all your source code and walk out the door in one's pocket. So the bad guys will find every seam in the fabric and use whatever tools are available to enter. Not sure which is worse....
Agreed. I think the overall challenge is best put as how to operate successfully in an open environment. What if you couldn't keep secrets? What are the minimum number of secrets to be kept? (SSNs, merger proposals, etc.)
You favor the Internet Engineering Task Force, the Internet's premier standards body which operates via rough consensus and running code. Here's something you didn't mention: It takes a long time for IETF working groups to finish standards, and sometimes (as in the case of instant messaging) they fail to get standards to market in time to stop proprietary solutions from taking over. What are your thoughts on that?
Yes, I think the IETF may be dead. (Sigh, I probably shouldn't have said that.) What I mean more directly is that the IETF functioned best in a backwater, when people were basically having fun, not taking themselves too seriously. As soon as people with coats and ties (Vint Cerf excluded, of course) started showing up, "rough consensus and running code" became harder to achieve. The story of ICANN is this story in a nutshell, how something -- the top level of the domain name system -- run by one guy with sandals, could become a $30 million+ / year operation and everyone still hating it and little getting done. I even see it reflected in the troubles of going from IPv4 to IPv6.
ScrumMaster offers tips on how to play in a winning dev team
How spyware nearly sent a teacher to prison
Open source identity: Asterisk founder and Digium CEO Mark Spencer
Fighting e-waste one mobile phone at a time
MIT's JoAnne Yates on information overload, 'CrackBerry' addicts and the 'always online' life
Read up on the latest ideas and technologies from companies that sell hardware, software and services. How to improve employee productivity in small and medium businesses
Mimosa™ NearPoint™ for Microsoft® Exchange Server: Email Archiving 101
Solve Exchange Mailbox Storage Issues Once and for All
Achieving the impossible: Unlimited application scalability
Business Intelligence and Enterprise Performance Management: Trends for Emerging Businesses
Best Practice in Building an Integrated Information Management Strategy
Gaining Competitive Advantage Through Enterprise Planning
The state of Middleware
Zones provide focussed content from Computerworld and leading technology partners.Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
FrontRange Solutions launches HEAT Plus Mobile to reduce help desk costs and improve service management productivity 2008-12-02 15:15:00+11
AARNet Helps to Advance Indigenous Health 2008-12-02 12:44:00+11
Orbis selects Telstra International as its data centre partner for the UK, Europe and Middle East Region 2008-12-02 11:23:00+11
ComOps Deploys Corporate Performance Reporting Solution For Healthcare Test Manufacturer 2008-12-02 10:09:00+11
Mornington Peninsula Shire implements Objective to manage knowledge and deliver service excellence 2008-12-02 09:56:00+11
Wireless LANs: Is my enterprise at risk?
Achieve an overall understanding of the risks associated with wireless LANs. Discover their inherent properties, as well as what makes them different from wired networks. Read on to uncover a list of recently published articles on real-life breaches and incidents illustrating the need for proactive measures to mitigate wireless security risks.












