On TV.com: BIGGEST LOSER Crowns a Winner
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 6 of 6:
« Previous
Has the right idea
Fundamentally we have a 'security problem' because we have decided to greatly depend on highly-complex IT that has a flaw rate about 1 to 2 orders of magnitude too high to have a chance against world-class threat sources. We call the latest buffer overflow a vulnerability. But in reality, that is not so much the vulnerability as it is just another symptom of the real vulnerability of over-dependence on fragile software. We continue to mistake the symptom for the cause. We are trying to deal with 100's of thousands of flaws one at a time. We are adding more software in the name of 'security' and likely as much increasing the number of flaws as mitigating business risk. That is why at this point the game goes to the attacker. And I think that is the reality behind Bruce Schneier's comments.

Bottom line: We don't want to trade off functionality for dependability. So we have a security community that enables us to do 'something' even if it really doesn't make much difference against the more serious threat sources. We are adding to what we already have instead of making the fundamental changes to it that are mandatory to really mitigate mission/business risks.
Posted by: gary.stoneburner   Posted on: 04/28/07 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

It's hard to secure your own products...  PB_z | 04/26/07
is that right?  the_fiddler_on_the_roof | 04/26/07
He's right to an extent  John L. Ries | 04/27/07
What a dope  ejhonda | 04/27/07
Nice sentiment, bad idea.  NotBornYesterday | 04/27/07
Has the right idea  gary.stoneburner | 04/28/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement

SmartPlanet

Click Here