iTnews
  • Home
  • Features
  • Technology
  • Security

Bruce Schneier on fighting security FUD

Staff Writer
Feb 1 2008 2:00PM
Follow google news

Security expert Bruce Schneier has long been critical of so-called security ‘theatre' - policies and products tailored to provide the perception of security rather than tackling actual security risks.


In his keynote address to Linux.conf.au this week he said information is our only effective security weapon, but that the computer security industry must not ignore the impact of fear and other emotions on individual and organisational behaviour.

In an interview with ITNews he elaborated on the challenges for the IT industry and the creators of security solutions.

If your job is to specify and create a security solution for your organisation, how do you neutralise the emotion and FUD (fear, uncertainly and doubt) to build the solution you want?

The only way to overcome it is through information. You have to counter people's natural reactions, their default ways of thinking. You need to make people stop and think about what they're doing. Sure it is hard but people in those positions do this all the time. In businesses, it's going to be easier. If you get it right, your business is more successful and you get more profits. So there's an incentive to get it right.

You seem to think that security vendors are part of the problem of 'snake oil' and 'security theatre' - does the IT industry need to do more to bring public perceptions about security closer to reality?

I'd like it if they did. The industry is good at FUD, but it's been crying wolf too many times. I'd like it if the industry would stop, but I don't know about 'needs to'.

You said in your keynote to LCA that information is the best weapon we have. But companies get penalised for disclosing security breaches through a lowered share price and lowered consumer confidence. So how can we as users trust the information which is available to us when companies have an incentive not to disclose it?

You can't. I can't tell you how much information about security breaches goes undisclosed - often victims don't even know they've been breached. You can call Gartner and they'll give you a number, but it's meaningless. We live in a capitalist society and you can't ask companies to voluntarily do things which are against their interests for the greater good. If they did, their shareholders would sack them.

In your talk you referred to the vested interests of governments and elected officials contributing to public misinformation about security issues. Last year the Australian government released a NetAlert internet filter to the public which was cracked by a schoolboy within half an hour. And the current government has a policy of bringing in mandatory ISP filtering. Is this typical of governments catering to the fear of the internet rather than making people more secure?

Sadly it is typical. Elected officials get re-elected if they make their constituents feel safer, so it's in their interests to do so. They'll buy stuff that doesn't work - like the RFID transit card system in the Netherlands which was cracked by a student in two weeks.

So which institutions can we look to to cut through the security theatre and obtain real information?

Things like disclosure laws. You make it mandatory. That works - everyone's in the same boat, no one company is penalised, you just changed the playing field. In the US the states have been bringing in mandatory disclosure laws - California was the first. If you lose people's data, you have to disclose. So companies started spending more money on security [to avoid breaches and the resulting damages from public disclosure].

Bruce Schneier is the founder and CTO of BT Counterpane. He's the author of several books on computer security and cryptography including "Beyond Fear: Thinking Sensibly about Security in an Uncertain World". He also publishes a monthly newsletter called Crypto-Gram, and publishes a blog.

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Tags:
brucefightingfudlinuxconfonschneiersecurity

Related Articles

  • Apple bumps up security in fresh operating system releases Apple bumps up security in fresh operating system releases
  • Meta accuses NSO Group of violating court order by WhatsApp spear phishing Meta accuses NSO Group of violating court order by WhatsApp spear phishing
  • Researchers build self-replicating AI worm with BYO LLM Researchers build self-replicating AI worm with BYO LLM
  • Anthropic opens Claude Mythos Preview AI program to Australia Anthropic opens Claude Mythos Preview AI program to Australia
Join our WhatsApp Channel

Partner Content

Onel Consulting Strengthens Its White-Glove Services With Strategic COO Appointment
Promoted Content Onel Consulting Strengthens Its White-Glove Services With Strategic COO Appointment
The hidden economics of AI: Why token usage matters more than you think
Partner Content The hidden economics of AI: Why token usage matters more than you think
Why resilient communications are becoming critical infrastructure for modern enterprise IT
Promoted Content Why resilient communications are becoming critical infrastructure for modern enterprise IT
Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026
Partner Content Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026

Sponsored Whitepapers

Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
High-volume data sources for AI-driven security analytics
High-volume data sources for AI-driven security analytics
How healthcare organisations can get more value from cloud
How healthcare organisations can get more value from cloud
1 in 3 companies lose SaaS data. Here’s how to prevent it
1 in 3 companies lose SaaS data. Here’s how to prevent it

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
  • Security Exhibition & Conference Security Exhibition & Conference
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Defence says Palantir is "sandboxed" in its environment

Defence says Palantir is "sandboxed" in its environment

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Microsoft backs down on legal threats against 0day disclosing researchers

Microsoft backs down on legal threats against 0day disclosing researchers

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.