All the latest UK technology news, reviews and analysis

Penny pinching firms make computer security worse

by Tom Sanders at RSA Conference in California

15 Feb 2006

Comment: 1

  • Tweet this
Software vendors lack any incentive to pay attention to security when they create their products
Despite some victories, computer security is getting worse, says Bruce Schneier

Computer security is getting worse as penny pinching firms put economics before the development of secure technology, according to Bruce Schneier, a renowned security specialist and the founder of Counterpane Internet Security.

"I think in general things are getting worse, not better," Schneier told delegates during a session at the RSA Conference in San José.

"There are lots of little victories. Spam is one of our industry's shining victories, but there are lots of areas where we aren't doing very well."

Software vendors lack any incentive to pay attention to security when they create their products, according to Schneier, and buyers are generally unable to determine the level of insecurity when they evaluate products.

This leads them to buy the cheapest product available on the market, which in turn forces developers that do emphasise security to lower their security levels in order to compete.

The security sector is using technology to solve the poor state of computer security. But technology is becoming less relevant now that networks have become an attractive target for criminals who have a strong incentive to exploit security vulnerability for financial gain, Schneier warned.

Security providers can create anti-spyware and security filtering software, but these applications are useless if consumers do not install them, he added.

"The fundamental driver in computer security, in all of the computer industry, is economics. That requires a lot of re-education for us security geeks," said Schneier.
The solution is to create economic incentives to improve computer security. " Make the entity in the best position to mitigate the risk responsible for the risk," he argued.

There are several ways to shift that responsibility, according to Schneier, but legislation and regulation are usually needed.

Requiring credit card providers to pay for fraud, for instance, has caused them to implement numerous security technologies and policies for merchants.

In the UK, meanwhile, Schneier pointed out that banks have done very little to tackle ATM fraud, because legislation makes consumers, not the institutions, responsible for fraud.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

44%

3%

12%

41%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Security Assurance Consultant

Security Assurance Consultant ( CLAS ) with HMG and Information...

Solution Design Architect

Solutions Design Architect - Oracle - Exadata - Dataguard...

Project Manager

My Client is a tier one investment bank based in Edinbugh...

Analyst Programmer

Analyst Programmer Web Developer required to work for...

To send to more than one email address, simply separate each address with a comma.