All the latest UK technology news, reviews and analysis

Human brains not wired for modern IT security

by Iain Thomson

More from this author

31 Jul 2009

Be the first to comment

  • Tweet this
Bruce Schneier
Bruce Schneier believes that computer security is unlikely to be solved in our lifetimes

Security expert Bruce Schneier told delegates at the Black Hat USA 2009 conference that the human brain is not suited to IT security in the modern world.

Schneier said in his address that, in evolutionary terms, the human brain cannot deal with the complex threats that dog the modern environment, and that computer security is unlikely to be solved in our lifetimes.

"We have Stone Age brains. We respond to stories not data," he said. "We are very good at living in small family groups in the East African highlands, but we do not have a lot of experience in the modern world."

Schneier suggested that this had a direct relevance to computer security in that humans tend to think along narrative rather than empirical lines. For example, having a firewall is perceived as a great protector of a computer, but in fact a poorly configured firewall is worse than useless.

He also cited biometrics and airport security as cases in point, where seemingly good security measures are actually counterproductive.

There are two key parts of the brain that respond to stress. The amygdala, which is one of the oldest parts of the brain stem, deals with the fight or flight reflex. This is present in ancestors as far back as fish.

But advanced mammals have the neocortex, which makes people think rationally about the potential risks. This is how humans mitigate risks and rewards.

"This only exists in mammals. It is the newest part of the brain, kind of still in beta testing," said Schneier, giving the example of someone getting a dressing down from their boss and not feeling inclined to stab the person or run away.

However, this logical reasoning comes with certain costs, and raises interesting questions from a security standpoint.

Humans are story-telling creatures, Schneier explained, and good stories capture our interest despite the fact that they may be factually harmful. This tendency in humans will make security a hard goal to reach.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Information Security Manager

My client is a well established, non profit organisation;...

PHP Web Developer

PHP Web Developer – £30,000 - £35,000 PHP, MySQL, HTML...

HEAD OF DIGITAL - London - £80-95K+

HEAD OF DIGITAL - London - £80-95K + Excellent Bens...

Agile C# Developer - (North London)

Agile C# Developer - (North London) £55,000 - £65,000...

To send to more than one email address, simply separate each address with a comma.