All the latest UK technology news, reviews and analysis

RSA: Security industry flooded with snake-oil

by Iain Thomson

18 Feb 2011

Be the first to comment

  • Tweet this

Experts have called for the IT security industry to improve its products and adopt universal testing metrics so that buyers can get a clear idea of what works and what doesn't.

Paul Kocher, inventor of the third version of SSL, said that the security industry lacks oversight, and that some products simply do not work as advertised.

Too many people are making money by selling a product and then charging to fix its initial failings, which is not a desirable business model.

"We need to have regulation or liability; at the moment we have neither," he said. "Some products are snake-oil. I suspect this will be decided by the lawyers."

Kocher pointed to the aviation industry as an example of best practice, where a full investigation is held after every crash. Flaws are analysed and design changes enforced among airlines and aircraft manufacturers to avoid the problem in the future.

Sal Stolfo, professor of computer science at Columbia University, complained that there is no agreed standard of testing to inform buyers.

"The industry needs to invest in testing to get rid of the snake-oil. There's a hodge-podge of metrics, but most of them are on how good malware is," he said.

"There are some cost metrics for intrusion protection systems, but it's not a science yet and it's underdeveloped."

Security expert Hugh Thompson agreed that there are too many poor products out there, although he pointed out that there are some reasonable metrics for cryptography.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

37%

0%

11%

52%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Availability & Capacity Lead

About Us WorldPay provides a globally connected, locally...

Change & Configuration Administrator

About Us WorldPay provides a globally connected, locally...

SQL Server Developer - SSIS - Zurich

SQL Server Developer - Our client, an international...

IT Technical Service Delivery Manager / ITIL / Reigate - 65K

IT Technical Service Delivery Manager / ITIL / Reigate...

To send to more than one email address, simply separate each address with a comma.