Schneier: Why rubbish security products win out

Bruce Schneier

Linux.conf.au kicked off its main proceedings in Melbourne on Wednesday morning with a stark message from security guru Bruce Schneier: "When security companies give you cost justifications, they're complete bullshit."

Schneier, author of the books Applied Cryptography, Secrets and Lies and Beyond Fear and described by outgoing Linux Australia president Jonathan Oxer as "a walking security advisor on the entire human race", told a sold-out keynote audience that IT security planning is rarely effective because it fails to take into account the emotional considerations involved in security.

Most security products either address perceived gaps in security and provide an emotional sense of stability without actually doing much useful, or solve actual problems but don't impart the same sense of security, he suggested.

"You can feel secure even though you're not, and you can be secure even though you don't feel it," Schneier said.

Want to know more?

For all the latest news, analysis and opinion on security, click here

"Making security trade-offs is something we do multiple times a day," he noted. "You'd expect human beings would be really good at making these trade-offs, but fundamentally we're hopelessly bad at it." The reason for that, he said, is that "we respond to the feeling of security rather than the reality".

Evolution means that pattern will be difficult to reverse, Schneier argued. "Our society is evolving faster than our species. Modern times are harder. Technology makes it harder, and the media makes it harder."

"People make the trade-off based on the feeling of security, not the reality. The economic incentives are for companies to make people feel secure. That's where you are rewarded in the market."

Drawing on George Akerlof's "lemons market" theory on the economics of information asymetry, Schneier said: "In markets where the seller knows a lot more than the buyer, bad products drive out good products -- and this is very much the case for security."

One notable problem, said Schneier, is the return on investment calculations for security software, which often draw on rare and devastating events to justify their cost: an approach which renders basic mathematics of little use.

"In IT, there isn't a lot of data -- this is one of the problems we have. You have to rely on emotion because we don't have the data. It's very hard to evaluate non-functional requirements."

Understanding of fundamental security principles also needs to dramatically improve, Schneier said.

"We know very little about software security. We can't even prove a program terminates, let alone that it's secure. We don't have a rigorous security methodology. It's going to be a long time before it can be applied to programs and systems and anything resembling actual commercial size."

Advertisement

Talkback 1 comments

  1. So what? Brian -- 30/01/08

    Governments get elected all the time promising to protect you from terrorists, muggers and losers of all descriptions, without any real possibility of being able to do anything about any of them. Perception IS reality. Statistics are irrelevant.


ZDNet's CIO Vision Series

Customs | Murray Harrison, CIO

Australian Customs CIO Murray Harrison dislikes SLAs and runs away if a vendor talks to him about innovation. In this interview, he also explains why getting excited about gadgets can be dangerous and talks about how Customs' outsourcing strategy has evolved.

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Munir Kotadia iPhone suckers test our patience
    So how many of you have bought a 3G iPhone? Do you feel like a sucker? If you don't, maybe you will once your first bill arrives.
  • Array Westpac bank: AVG's toughest competitor
    The next time you're buying antivirus software, don't go direct to Symantec or McAfee. Don't download free antivirus. And definitely don't see Harvey Norman. Ask your bank — they're quite literally giving the stuff away.
  • Array Will you manage in the exabyte era?
    Mammoth growth in storage volumes is a fact of life, but even so it's helpful to pause occasionally and try and work out whether our information strategies have fallen hopelessly out of step with the pace of technological growth and changes in costs.
  • More blogs »

Tags

Back to top

Featured