Skip to navigation
   
Simon Bisson & Mary Branscombe's Blog

From security theatre to security cabaret, or why too much security is worse than none

By Simon Bisson & Mary Branscombe in Editorial

Posted in People, Business, Identity, Futures, Security on April 12, 2008 at 6:46 am

Permalink | Author Profile

Security theatre is what security expert Bruce Schneier calls measures designed to make us feel safer that don’t actually make us any safer at all. He discussed the positive effects of this at the RSA conference this week; flying is one of the safest forms of transport and if having to take off your shoes and abandon your bottle of water make you feel that airport security is good enough to catch terrorists and you fly rather than taking a more dangerous method of transport, then the security theatre has made you more secure.

Here’s another paradox. Too much security makes you insecure. If someone in your company is emailing customer information to their Gmail account and copying market forecasts to their laptop and keeping old price lists for months after they’re out of date, it’s more likely that they’re just trying to get their job done on the road than that they’re stealing data to pass to a competitor - and that you didn’t give them a better way to do it. Make it impossible to do my job securely and I’m going to break or bypass your security so I can actually do my job.

The wireless network at the RSA conference was a good example of this. It was secure. Very secure. So secure that without the five pages of instructions I didn’t manage to get connected, and I didn’t meet anyone else at the conference who managed it either. If I’d wanted to hack into the laptops of anyone at the show, I wouldn’t have tried to steal them. I’d have set up an open free wi-fi connection on the show floor and everyone would have connected to that instead, giving me a great opportunity to see anything that didn’t go through a VPN.

Hugh Thompson of People Security has a good grasp of security and security theatre; you’ll have seen him if you watched Hacking Democracy, the documentary about the security problems with voting machines. He closed the conference with a chat show that ranged from a funny song about SQL injection (not a very funny song, but still) to Eric Drew’s tale of having his identity stolen by a lab technician at the hospital where he was being treated for leukemia and tracking the man down himself (a story Drew makes funny in the retelling that would have been a tragedy if he wasn’t in remission).

Thompson had a semi-serious conversation with Bill Cheswick, co-inventor of the firewall. Cheswick jokingly referred to malware as a “denial of spare time attack” that at least means you spend time with the family and friends who ask you to fix their computers. He was also slightly tongue in cheek when he said that he hadn’t used a firewall in a decade because he wants to use a secure computer instead; “it’s that whole crunchy outside, chewy centre thing; now we have much bigger liquid centres and once you’re past the outside you have access to everything.” But Cheswick also had some serious predictions to finish off Thompson’s security cabaret.

  • “IPV6 has been three years away for the last 15 years. We’re finally approaching it - so all those firewall rules are going to need redoing. That will be fun…”
  • “More attacks are going to come in through the browser so it may not matter so much what that the OS underneath is. You go to the wrong page, or the right page that has the wrong advertising agency - you did the right thing on your site but the other guy got hacked. To deal with that there’s going to be more sandboxes. I want users to be able to do everything online. I want them to run free in a sandbox. I used ASCII email for twenty years. ASCII email is safe but you want to be able click on the pictures.”
  • “Computers are going to get better. We’re in the barnstorming era now. We’re going to look back and say ‘remember when you had to be careful about what you clicked on?’”.
12345
Not yet rated
Loading ... Loading ...

Previous Post | Next Post

 
 
Comments

Trackback by Maurita Juneja - February 9, 2012 on 3:41 am

will smith and jada pinkett house…

[…]against Lennox and his family is now out of the palms of Belfast City Council […]…

Trackback by Marcellus Antrim - February 9, 2012 on 7:57 am

greenpeace logo…

[…]I wouldn’t be capable to pursue all of these different goals while at the same time dedicating the energy […]…

Make a comment

* required

* required

We stop spam using reCaptcha.
Type the words below and click Submit Comment.

   
Tag cloud

offload Visual Studio bandwidth HP safend ClipMate applications bea fingerprint scanner Windows Mobile Tripit Microsoft Palladium Loki rc T-Mobile catalyst visualisation pen computing mobile ofcom network distributed computing cold fusion bbc iplayer flash mobile network Tablet Kiosk cam bolt storage media Istanbul patent HTC remove back netbook teched NVIDIA information security theatre etech disaster recovery Bill Gates cracking NGSCB Intel goview firewall identity theft networks community evernote Active Directory cloud service google online applications cloud computing Safari Silverlight nvision08 netiquette history ruggedized robot ontier designer BlackBerry acquisitions virtualisation semiotics emulator CIO IDF Crossfader cables NexT vulnerabilities ports Itanium anti-virus d2c camera Mono hard drive Gears Jeff Hawkins macro Secunia 965 downturn lawsuit hardware power Girl Geek Dinners enterprise SSD flash drive performance yahoo city HSPA mobile Linux MacWorld 2008 Netscape transcoding AskEraser isps OpenID bombe NAS dual display numbers development consolidation business technology optimisation server sprawl DOSBox radeon system center MRDA TouchSmart database Chrome DOS ATI regulations mms 2009 Bing web 2.0 expo Firefox Ask.com appstore WWW Ruby ipsec OEM CES disk merger gameboard trends .NET html microsoft research GPU migration installation icons Windows Server isp innovation Trolltech gaming DSL Fire Eagle biometrics identity metasystem advertising cosmic rays competition accessories gamer HMT interoperability power saving mobile broadband appzero old software user interface Volume Shadow Copy collaboration Greasemoneky video green IT it pro upgrade CPU search MAX mscape logitech Nokia vmware conferences SP1 annotation eu apps geocaching anti-patterns active digitiser green printing WEI Hp 2710p SMB 2 relocation HTML 5 voice people data loss prevention fingerprint timezones software case Mercury deperimeterization Treo Pro 2.0 data xT9 CUDA rtm ubuntu Sony HSDPA TSA wildfire oracle geek tourism multiple monitors Vista iPass insert SIM legacy user experience private cloud web fault dvi ribbon mythbusters Enterprise 2.0 SBS ultraportable spam fighting fire Verbatim co-processor Mozilla mysql data centre RIA tablet web2expo Clear RX IT value Tombstone Objects TechEd 2008 cloud WPF virus Skyfire Motorola Pal Xen london Linux windows claims spam DisplayLink WinHEC lost server Tablet PC Acrobat Pro IT automation exchange security paradox Magny-Cours future in review information rights management wave moblin Netscan winhec2008 maps Web 2.0 design AMD Facebook browser OFCOM quiz IM pixetell business continuity setup international roaming FUD Opera bugs infrastructure credit crunch business model Protected View Windows 7 vs Windows Vista terabytes direct access Opsware patch Tuesday enterprise architecture service oriented enterprise geotagging greenplum MWC Internet backhaul deborah adler information cards Palm business technology automation beta wireless USB identitity education Previous Versions Mini-Note social networking hyper-v navigation MIX legislation bug atom wifi LiveID phone settings Google IO culture hacking todo list webkit telecoms MacBook Air high performance computing mash-up october GPS g-1 MING iPhone battery life power cuts streaming media Mark Hurd Adobe p2v images keyboard Delphi SapphireSteel RSA 2008 venture capital geneva Beacon g-2 conference docking station exabytes Location IT transformation RSS search control panel Frauenhofer mobile data tariffs Reqall task bar optical interconnects android fonts ipv6 data tariff developer traffic how do I get the back off? Smartbook ucsd installer macbook IIW2008b hibernation magic pgp DLP BitLocker natural interface cellcrypt Nuance desktop. PC windows 7 display cisco office 2010 mobile working LHC Ray Ozzie EMC licensing O'Reilly no signal troubleshooting wubi Apple congestion charge navteq demo09 training mobile Wimbledon Tim Berners-Lee hold music netbooks benchmark open source data loss Toshiba Portege R500 thermo disk space routing clean install context fibre secure wes IBM sun futura business anti-trust hierarchical temporal memory BBC Windows Live social engineering Seagate ikea ANR screencam IT policy power supply Internet Explorer 8 office phone management Bill Cheswick ProCurve Wyse Trend Micro T9 toshiba BT project GPL hp microsoft research turing application compatibility RIM Google Sets microsoft security essentials Opteron uninstall amazon demo Embarcadero twitter national museum of computing RBL Credentica QWERTY tennis processors Windows Server 2008 electricity price Qualcomm 3G Lenovo Live Mesh flex IO email Express Gate privacy CardSpace EEE whitelist politics security codec drivers moscow Java Jeff Jones target CTO Numenta gabriola aws augmented reality i-mate M&A 64-bit system management outlook Salesforce pre-boot Eee PC virtual desktop bletchley park parallel computing regulation switch Hugh Thompson utility tele atlas accelerator Quest ec2 Moonlight mobility police Google Spreadsheets public cloud productivity management citrix SKU office politics VSSAdmin colossus Trampoline MIX08 screen hdmi Tom Hogan data centre transformation 2009 utilities AIR laptop griffin machine learning mainframe Large Hadron Collider Dell business intelligence christmas malware market share adfs analytics ballmerbot RAZR Internet Explorer Corsair meaning AuthenTec O2 lockdown mapping thin client CERN Gartner open OQO Google voice recognition media center network UMPC Barracuda smartphone Xobni Dopplr forensics windows server 2008 r2 rich client instant messaging workflow encryption dual boot support monitor Asus verdana Ruby On Rails server connectivity calit2 beta test BES Vodafone usb ADFS 2.0 amherst
Advertisement
Advertisement