Is desktop security broken beyond repair?

Get Adobe Flash player

At the AusCERT 2007 conference in Queensland last week, keynote speaker Ivan Krstić, who is the director of security architecture for the One Laptop Per Child (OLPC) project, told attendees that desktop security was fundamentally broken. We asked several security experts who attended the conference if they agreed and how the problem could be fixed.

Krstić's conundrum, as he explained to ZDNet Australia shortly after his presentation, was that the industry's approach to desktop security has been to shift responsibility of security matters to the end user.

"We need to understand that users are not people who have degrees in computer science and a deep understanding of computer security -- they are people who are trying to get their job done.

"Weaseling off responsibility for security to users might make sense for some vendors to do in terms of legally protecting themselves, but its not actually helping the end users," he said.

Krstić advocates that the desktop should resolve more security matters automatically -- and not rely on input from a user that has as much potential to compromise a system as protect it.

The 'dialogue box', used by operating systems and security software vendors to warn or protect users when they are about to make a crucial decision, is the "scourge of desktop security", he said.

"If you go to a Web site whose security certificate is for any reason not checking out, you get a dialogue box that you [require] strong Internet security [skills] to decipher," he said. "For anyone else, they get to do a random guess between yes, no and cancel. That's no way to protect anyone," he added.

Reaction
Tech-philosopher and hacker guru Richard Thieme said that Krstić was absolutely right: "He said things that everybody here knows are true, but we're trying to patch it and catch up with it".

James Turner, industry analyst at IBRS, said users should not be in complete control when it comes to important security measures. In his "dim, dark past" as a systems administrator, he took particular grievance when Microsoft's operating systems allowed the local user to have administrative rights on their own laptop.

"It was suicide for the organisation," he said. "And the people who were writing malware out there took massive advantage of that over the last few years."

Bradley Anstis, director of research and development for security vendor Marshal, said Krstić's theory was a thought-provoking one -- one in which he and the vendor's engineering team will be taking into consideration as they "start to write the applications of tomorrow".

Other participants at the conference were more critical -- claiming that Krstić wasn't taking into account neither the human desire for choice nor the gains recent operating systems have made into solving the issue.

"What bothers me the most is that he's leaving user choice out of the decision," said IBM chief security engineer, Anthony Nadalin. "I just don't think the policy decision should be made by the process itself. I still believe that the human needs some level of interaction."

"I agree that interaction has to be very minimal and very basic so people can understand it. But people have to have a choice," he said.

Alagu Periyannan, CTO of BlueCoat, said that the problem with older operating systems is that user privileges have automatically translated to the application the user is running, regardless of the type of application or how it was installed.

"You can start seeing in the newer versions of desktop Linux, or even Mac OS and Vista, they've started to separate that out," he said. "If applications are starting to do certain things, the user is prompted as to whether they want the system to do this."

Andy Solterbeck, vice president of enterprise security at SafeNet, agreed: "Windows Vista has had a significant improvement in the underlying security architecture," he said.

Better interface required
All of the attendees agreed the way security choices are presented to users is too complex.

"Most people are lay users -- you can't be prompting them to change file permission, they aren't going to know what that is," said Bluecoat's Periyannan. "The art really is in making that really simple. It's about giving them the right security aspects but not nagging the user with questions he's never going to be able to answer."

IBM's Nadalin said: "You have to have a metaphor presenting things to the user ... Today that metaphor is not very friendly and that's what has to change in the industry. We have to have better ways, better icons."

Nadalin believes the industry should agree on some basic symbols and modes of communication that users can learn and rely on, in the same way the world has (almost) universal codes for traffic signals.

"We've gone along and decided what street signs mean right across the world. Why can't we do the same things for privacy aspects or release of information?

"We have these universal icons that mean certain things. We could have a caution sign -- people understand caution -- we could have another particular icon [refer to] privacy. I think there's way to get around [Krstić's] particular set of concerns," said Nadalin.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

ZDNet Australia Live

Android's biggest security flaws| ZDNet Australia http://t.co/oVIpu1PE

Android's biggest security flaws| ZDNet Australia http://t.co/ApyNPcUF

It's easy to rubbish an old operating system long after the rest of the world has already passed judgement upon it. I would be far more i...

34 minutes ago by ramnet on Microsoft admits Vista was 'cheesy'

Spotify launch suffers redirect bungle http://t.co/qUkSYPJB via @zdnetaustralia

Best user comment: "If Vista is cheesy, Metro is an over-ripe Stilton." http://t.co/ZJUwaxJT

If Vista is cheesy, Metro is an over-ripe Stilton.

49 minutes ago by meski on Microsoft admits Vista was 'cheesy'

A farewell to democracy: Kaspersky - ZDNet Australia - A farewell to democracy: KasperskyZDNet AustraliaWithout inte... http://t.co/4Chwa6uL

A farewell to democracy: Kaspersky http://t.co/mOhiBgDu

Spotify launch suffers redirect bungle http://t.co/EZeHfNeb

RT @zdnetaustralia: What are Android's biggest security flaws? http://t.co/SJoTiDUY ^ST

Chief Marketing Officer - the hottest seat in the C-suite http://t.co/Gfnvwm7c

you are kidding right - what qualification do you have to make such wildy stupid statements - do you really have customers who pay you fo...

1 hour ago by rant rant rant on National Botnet Network coming: Earthwave

Spotify launch suffers redirect bungle - ZDNet Australia http://t.co/VmBsbPL8

Spotify launch suffers redirect bungle - ZDNet Australia http://t.co/E1kTrltd

Spotify launch suffers redirect bungle http://t.co/8UP4lyd1

by http://t.co/vmlQ0Ecb: Spotify launch suffers redirect bungle: Spotify's Australian launch seems to have failed... http://t.co/FRd6qAFw

Spotify launch suffers redirect bungle http://t.co/KPzJd2I8

Chrome overtakes IE: does it matter?: Google's Chrome appears to have become the most-used browser, having surpa... http://t.co/RJH13wPw

#Qantas promotes Strategy & Technology Head to #Jetstar CEO role from July 2012 http://t.co/bn5lmRRe

Monday madness Anonymous hacks Bureau of Justice http://t.co/GZ2jD9iO

A farewell to democracy: Kaspersky - ZDNet Australia http://t.co/I4NUagc8

A farewell to democracy: Kaspersky - ZDNet Australia http://t.co/50zNZ6O3

Spotify launch suffers redirect bungle: Spotify's Australian launch seems to have failed on at least one level: ... http://t.co/9btrXux2

Spotify launch suffers redirect bungle: Spotify's Australian launch seems to have failed on at least one level: ... http://t.co/9BvAawhj

A farewell to democracy: Kaspersky - ZDNet Australia http://t.co/qXfkgh8l #australia #technews

Spotify launch suffers redirect bungle: Spotify's Australian launch seems to have failed on at least one level: ... http://t.co/9BvEI6id

A little QA goes a long way. Spotify's redirection bungle http://t.co/NL5gCATG ^ST

Kaspersky says that democracy is threatened if we don't get a handle on e-voting http://t.co/w4Wgrqod ^ST

RT @lukehopewell: Eugene Kaspersky: without online passports, democracy will fall apart within 20 years http://t.co/nkNPUcph [COOL!]

BigAir acquires Qld wireless carrier - Communications - News - ZDNet Australia | @scoopit http://t.co/mha59x9x

Kaspersky's farewell to democracy: without online passports, democracy will fall apart within 20 years - http://t.co/w4Wgrqod ^LH

Android's biggest #security flaws: Android is widely accepted as being iOS' greatest rival, but, according to De... http://t.co/nVdKxBCD

BigAir acquires Qld wireless carrier http://t.co/ARFQmWqa

IBM bolsters big-data line-up with Vivisimo http://t.co/K2z8KrtP @zdnetaustralia

IBM bolsters big-data line-up with Vivisimo http://t.co/B6IOVeDv @zdnetaustralia

EU antitrust chief: We'll settle with Google http://t.co/9E7EEuAi

Chrome overtakes IE: does it matter? http://t.co/cTBwlULz

BigAir acquires Qld wireless carrier http://t.co/27vGpBMN

Exactly. There are two topics of discussion, that are co-mingled; 1) Unauthorized software was put on the company device, by an IT person...

4 hours ago by lamont on ABC's Bitcoin miner tackled in minutes

Of course, it's true and it may be quite unnerving and mind-boggling, to begin thinking about selling or buying precious jewelry. This, o...

9 hours ago by Sanchezgavi5 on Don't add Telstra deal to NBN cost: Quigley

First off, Bitcoin is not a virus. Second off, the only way to generate Bitcoins, is by using a Bitcoin miner. More information on this h...

14 hours ago by rizowski on ABC's Bitcoin miner tackled in minutes

When an operating system is sold it should not launch until an approved security service is purchased online with a list of approved supp...

14 hours ago by Kevin Cobley on National Botnet Network coming: Earthwave

Admits? Don't fall for their marketing. Vista was beautiful. Microsoft has a history of trashing their older OSes.

20 hours ago by anonymuos on Microsoft admits Vista was 'cheesy'

Gotta agree. For our Burnie, Tas. internet, we have a 1.5MB download speed adls connection through exetel using testra copper line. ADS...

20 hours ago by brozza on Broadband Speedtest

Well the message certainly is clear. Never do anything because something might happen. Seriously it seems to me "Earthwave" just want to...

22 hours ago by Hubert Cumberdale on National Botnet Network coming: Earthwave

you really think it's going to be such a grim future? looking at South Korea, Japan, even Czech Republic - I haven't seen either emit mo...

1 day ago by romant on National Botnet Network coming: Earthwave

No... they'll just blame the NBN for that too ;-)

1 day ago by Beta on National Botnet Network coming: Earthwave

It seems that some of the people who set up ACCAN (not staff members) took the view that it would somehow be against their view of 'consu...

1 day ago by socrates on ACCAN gets govt tick amid industry criticism

Don't laugh, Mr Turnbull is dumb enough to try and use this against the NBN. I'm sure the noallitions magical FTTN will be impervious to ...

1 day ago by Jingles on National Botnet Network coming: Earthwave

OMG, the sky will fall if we get NBN - it must be cancelled immediately! Sorry; was just channelling Malcolm Turnbull there for a moment...

1 day ago by socrates on National Botnet Network coming: Earthwave

Thats just stupid.. what else is the NBN going to get blamed for? People die crossing the road, are you going to ban cars or police it b...

1 day ago by fibretech on National Botnet Network coming: Earthwave

And again - missed this bit did you? "... Telstra is responsible for estates where development approval was granted before 1 January 201...

1 day ago by Beta on Copper greenfield dominance irrelevant: Conroy

I think the idea of dropping aero glass bit of a mistake. At least have some colour. Thats something i liked (especially after working on...

1 day ago by JCOZ on Microsoft admits Vista was 'cheesy'

Yes, most people hate the processes put in place to ensure purchasing is fair, transparent and above board. Having been a purchasing off...

1 day ago by ozguy2000 on Woolies case poses procurement questions

God,..why spend another $6.7M on a system that's never going to be any good & never work in all probability!.. \ Government bureaucrats ...

1 day ago by Keith Styles on Vic scraps HealthSMART system

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar