Tuesday | 7 October, 2008
Computerworld
Bruce Almighty: Schneier preaches security to Linux faithful
Schneier is one of three keynote speakers at Linux.conf.au 2008 and speaks with Dahna McConnachie about his presentation, books and thoughts.
Dahna McConnachie 27/12/2007 07:56:29

Bruce Schneier will reconceptualise security at Linux.conf.au
Bruce Schneier will reconceptualise security at Linux.conf.au
Computerworld Buyer's Guide - Vendors Matched to this Article
Related Features
  • +

    Process Trip 04/02/2008 13:07:03

    Why Maritz Travel revamped key business processes — and how business and IT came together to make it work
    When Rich Phillips became COO OF Maritz Travel about two and-a-half years ago, he sat down and took a hard look at the big industry picture
  • +

    Ticked Off at Tick the Box Mentality 04/02/2008 13:01:15

    Does your executive search firm know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
    Does your executive search firm know its MIS managers from its elbow? Does it even know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
  • +

    How to Get Real About Strategic Planning 04/02/2008 12:50:59

    Everyone agrees that having a strategic plan for IT is a good thing but most CIOs approach the process with fear and loathing. In fact, the majority of CIOs (and the enterprises they work for) are faking it when it comes to strategic planning. Isn't it time we all got real?
    Oh, it must be nice to be the CIO of a FedEx or a GE or a Credit Suisse. Places where IT and the business are so tightly aligned you can barely tell the two apart. Where corporate leaders understand that IT is a strategic asset and support it as such
  • +

    Toxic Mix or Bit of a Mixed Blessing? 31/12/2007 10:36:30

    “Eye of newt, and toe of frog, Wool of bat, and tongue of dog . . . ” The inter-generational office brew of Boomer, Gen X and Gen Y may not be quite as odious as that of the three witches in Shakespeare’s Macbeth, but even so it makes “for a charm of powerful trouble”
    "Eye of newt, and toe of frog, Wool of bat, and tongue of dog . . . " The inter-generational office brew of Boomer, Gen X and Gen Y may not be quite as odious as that of the three witches in Shakespeare's Macbeth, but even so it makes "for a charm of powerful trouble"
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.

Newsletter Subscription

Sign up for our Computerworld newsletters!
Computerworld's twice-daily news service keeps you in touch with the latest, most important headlines from Australia and around the world.
Keep up with the latest virtualisation technologies, products, news and features.
RSS Feeds

Internationally renowned security guru, Bruce Schneier, will be encouraging technologists at linux.conf.au to take a lesson from Luke Skywalker, and "feel the force" a little more when it comes to security.

Schneier, who is CTO of BT Counterpane, is one of the three keynote speakers at the 2008 Linux.conf.au. He joins Python release manager, Anthony Baxter and founding member of HP's Linux division, Stormy Peters.

Dahna McConnachie speaks with Schneier about his talk, "Reconceptualising Security" and how technologists need to remember the importance of the human element. He also discusses cyber-war, what Linux has done for security, and the likelihood of another edition of Applied Cryptography.

What do you spend most of your spare time working on these days?

Much of my work these days involves the human motivations around security: the economics of security, the psychology of security, and so on. Again and again I see good technology failing because these aspects of the security system haven't been well thought out, and these social science communities have a lot to teach us in computer security.

(Read some of Bruce's recent thoughts on the psychology of security here)

What will your keynote talk "Reconceptualising Security" be about?

Security is both a feeling and a reality, and they're different. You can feel secure, even if you're not. And you can be secure, even if you don't feel it. Really, there are two different concepts sharing the same word. My talk is about the feeling and reality of security: when they are different, why they diverge, and how they can be made to converge. As technologists we tend to focus on the reality of security and ignore the feeling. I will argue that both are important.

Do you think that technologists sometimes forget about the human element generally when designing, developing, testing, implementing and/or maintaining systems?

Sometimes? I think they forget almost all the time.

One of the messages you preach is that organisations need more than secure algorithms to be secure. Can you synthesise this argument, in terms of what it means, particularly in today's Web 2.0 environment?

Security is fundamentally a people problem. It doesn't matter how many bits your encryption algorithm has if your employees go home and blog about your company's secrets.

Analysing the security stories that make the news is one of your pastimes. Is there a disparity between what gets covered and what matters the most?

I think the media covers security stories more or less at random: they cover stories that aren't important, and they miss ones that are important. Largely, this is because the stories can be complicated and technical, and reporters don't have the expertise to separate what's important from what isn't.

Computerworld Buyer's Guide - Vendors Matched to this Article
Market Place

Computerworld Member Login


 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
Whitepaper

Optimized Back-up and Recovery for VMWare for VMWare Infrastructure with EMC Avamar

Virtual machines deployed in the data centre must be protected against failure. Read on to find out how to extend data protection to your virtual machines.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links