iTnews
  • Home
  • News
  • Technology
  • Security

Information is our only security weapon: Bruce Schneier

By Sarah Stokely
Jan 30 2008 12:44PM
Follow google news

Computer security expert Bruce Schneier took a swipe at a number of sacred cows of security including RFID tags, national ID cards and public CCTV security cameras in his keynote address to Linux.conf.au this morning.

Information is our only security weapon: Bruce Schneier
These technologies were all examples of security products tailored to provide the perception of security rather than tackling actual security risks, he said.

“Camera companies are pushing it, but all the actual data points the other way,” Schneier said. “RFID is another one – the industry pushing it is very much distorting facts.”

The discussion of public security -- which has always been clouded by emotional decision making -– has been railroaded by groups with vested interests such as security vendors and political groups, he said.

Public discussion which should be a security debate can be coloured by politics, he said.

"In the US, a lot of security discussions become political - my side good, your side bad. It's very hard to say 'I'm going to defer to the experts' because the political sphere is so polarised there are paid experts on all sides."

It will take a generation before US attitudes towards public security move beyond the post-September 11 climate of fear, he added.

The lesson for the computer security industry is to cater to real security issues while also considering the impact which fear and other emotions have on individual and organisational decision making.

Historically, the computing industry is littered with good products which failed to gain market traction over less secure solutions, he said, pointing to the firewall market as one example.

Schneier noted that despite the well known impact of emotional and psychological thinking on security decisions, information remains the greatest weapon that we have in creating good security solutions.

The best security solution will fail if it doesn't cater to both the reality and perceptions to do with security, Schneier warned.

"For most of my career I would insult ‘security theatre’ and ‘snake oil’ for being dumb. In fact, they're not dumb. As security designers we need to address both the feeling and the reality of security. We can't ignore one.

"It’s not enough to make someone secure, that person needs to also realise they’ve been made secure. If no-one realises it, no-one's going to buy it," Schneier said.

The goal must be to get the reality and perception matching up – so that security solutions aren’t lulling users into a false sense of security, or letting them exist in an unnecessary climate of fear.

"How do you stop the stupid stuff from outweighing the reality? The way to get people to notice that reality and feeling haven't converged is information. Information is the best weapon we have.”

In the IT industry, this information is a scarce resource, he said.

"In IT there isn’t a lot of data. Our bosses ask us for it all the time. We don't have the data because people don't report or they don't know they've been attacked.

"If there's enough information out there, you get a natural convergence between feeling and reality. In the business world, information is how the problem fixes itself," he said.

Bruce Schneier is the founder and CTO of BT Counterpane. He's the author of several books on computer security and cryptography including "Beyond Fear: Thinking Sensibly about Security in an Uncertain World". He also publishes a monthly newsletter called Crypto-Gram, and publishes a blog.

Find out more in this exclusive interview with Bruce Schneier on fighting security FUD.
Got a news tip for our journalists? Share it with us anonymously here.
Tags:
informationislinuxconfonlyourschneiersecurityweapon

Related Articles

  • Single Windows image drove RedVDS disposable cybercrime server business Single Windows image drove RedVDS disposable cybercrime server business
  • Microsoft patches single-click Copilot data stealing attack Microsoft patches single-click Copilot data stealing attack
  • Vic Education database breached via school's network Vic Education database breached via school's network
  • Researchers unsure of purpose of new VoidLink Linux malware Researchers unsure of purpose of new VoidLink Linux malware
Join our WhatsApp Channel

Partner Content

Identity at the Centre: Why AI Is Accelerating a New Security Imperative
Partner Content Identity at the Centre: Why AI Is Accelerating a New Security Imperative
Cyber Engineering launches at ctrl:cyber with former Shelde founders
Partner Content Cyber Engineering launches at ctrl:cyber with former Shelde founders
ctrl:cyber strengthens sovereign cyber capability with elevenM acquisition
Promoted Content ctrl:cyber strengthens sovereign cyber capability with elevenM acquisition
Suntory Oceania’s $30 million IT transformation powers carbon-neutral multi beverage facility
Partner Content Suntory Oceania’s $30 million IT transformation powers carbon-neutral multi beverage facility

Sponsored Whitepapers

Fintech compliance made fast and secure
Fintech compliance made fast and secure
How to evaluate SIEM solutions Safeguarding your future Get a demo Download guide
How to evaluate SIEM solutions Safeguarding your future Get a demo Download guide
2025 Security operations insights: Three-quarters of security leaders need something new in SIEM
2025 Security operations insights: Three-quarters of security leaders need something new in SIEM
Sumo Logic named in the 2025 Gartner Critical Capabilities for Security Information and Event Management (SIEM)
Sumo Logic named in the 2025 Gartner Critical Capabilities for Security Information and Event Management (SIEM)
The cloud tipping point
The cloud tipping point

Events

  • iTnews Executive Retreat - Security Leaders Edition iTnews Executive Retreat - Security Leaders Edition
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Services Australia to tap law enforcement data for staff security

Services Australia to tap law enforcement data for staff security

Aussie teenager charged with swatting US retailers and educational institutions

Aussie teenager charged with swatting US retailers and educational institutions

Vic Education database breached via school's network

Vic Education database breached via school's network

Cloudflare DNS reply change crashed Cisco SME switches

Cloudflare DNS reply change crashed Cisco SME switches

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.