, 2004-03-29
Social engineering in the latest crop of viruses has people jumping through hoops to open malicious attachments. How do we change the pattern?
Expand all |
Post comment
Human Nature vs. Security
2004-03-30
IT Professional (2 replies)
IT Professional (2 replies)
Human Nature vs. Security
2004-03-31
jaywalker (3 replies)
jaywalker (3 replies)
Human Nature vs. Security
2004-03-31
Anonymous (1 replies)
Anonymous (1 replies)

In small transparent societies with a uniform culture that worked well. The problem is that most societies aren't uniform nor small anymore. Sure, you'll find exceptions, like Amish people who don't bother to lock their doors, or remote mountain passes where the turnpike fee is paid by leaving money in an envelope for the gate keeper.
There's only two real solutions to the problem -- either trade convenience for ever-increasing security measures, or force untrusted people away from the society (eggshell method -- hard on the outside, soft on the inside), keeping it small and uniform enough that the lessened security model works.
A firewall appliance is a good example of the second solution. The problem is that people invite strangers in, be it by email, P2P or otherwise, and expect people on the outside to be as well behaved when they visit there. That won't do.
An antivirus program is an example of the first measure. Unfortunately, that won't work either, both because there's a limit to how much security can be imposed and still have a working system, and because people are quite frankly too lazy to implement and keep current adequate security measures.
What I see as the *only* solution here is education. Forced education. A driver's license to be able to use the Internet services, with sizeable fines for not having a license or not following the rules.
If it's voluntary, people won't learn, and WILL open and run the britney_spears.scr that apparently was sent by cousin Phil in Oregon.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/231/25640#25640