Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Security Analogies
Scott Granneman, 2007-05-29

The following is a written version of a speech I gave at The Open Solutions Summit (AKA LinuxWorld NY) in New York City in February. It's long, but I think you will find it interesting. If you want to get to the website I announced, jump to the last section.

Comments Mode:
Security Analogies 2007-05-29
Anonymous
Scaring people isn't working anymore 2007-05-31
Gordon Fecyk
Limitations to Security Analogies 2007-05-31
S Lo Presti
Security Analogies 2007-06-01
Anonymous
Security Similes. 2007-06-04
jreid
I have a number of useful similes that I use to describe technology (which is, technically, an analogue of the process it implements), but I use them to solve problems for clients. Just as people should understand the concept of a "cold" or "infection" to rationalize certain preventative behaviours, they should apprehend a basic concept of their systems being "at risk", "vulnerable" or "exposed".

However, what the security business has accomplished so far is instill a sense of (perhaps justified) unease about the reliability of computer systems. More mature professions have compensated for public unease by focusing on the "well being" of the customer. (The conversation, "Am I sick?", "How do you feel?" should be familiar to anyone who has visited a doctor.) Analogies are part of the answer. The other part is training geeks to provide confidence and assurance to customers to help make decisions instead of tedious, fastidious explanations.


[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/445/34582#34582
Security Analogies 2007-06-05
Vladimir
Security Analogies 2007-06-07
http://blog.purepistos.net
Security Analogies 2007-06-08
Anonymous (1 replies)
Re: Inconceivable! 2007-08-09
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus