Bruce Schneier is one of the foremost experts on cryptography and is a well-known security author and commentator. He is the founder of the managed security services company Counterpane, which was acquired in October 2006 by BT. Schneier sat down with IDG News Service at the Infosec security show in London to talk about the effectiveness of security products and the psychology of security.
IDG News Service: Are anti-virus products just making money by giving people a "feeling" of security rather than true security?
Schneier: Anti-virus is easy. Anti-virus products actually work. They have for years. A lot of the software on this show floor is just snake oil, but anti-virus does work. You should have an anti-virus program. You should have it updated regularly. It doesn't make you secure, but it gets that bottom layer of the trivial stuff. That's why. It's not sufficient but it's certainly necessary.
IDG News Service: People are tricked into downloading malicious software through social engineering. Have people become too conditioned -- mainly through watching television -- to also believe whatever appears on their monitor?
Schneier: Yes, but it's not television. People know the Internet is not television. People believe what they see on the Net not because of television but because of the trappings of reality. So when you got to BT.com, you see the BT logo, the BT font, the PR material, and you'll think, yeah, it's BT, like when you go to your bank, you see the logo, the tellers. That's real, that's expensive stuff.
On the Web, it could be a fake BT.com site and you don't notice because it's trivially easy to copy. So people do believe what they see on the Internet, not because of television, but because the Internet has the trappings of the real world. So all of those social cues you get to know to trust something -- it looks professional, nothing's misspelled, you see those things and you believe it's real. So yes, people are conditioned to accept it but it's from a whole variety of social conditioning.
IDG News Service: Do you think people will ever gain a greater suspicion of the Internet?
Schneier: Younger people have better bullshit detectors and they'll pick it up. But certainly you can always fool people unless there is some external validation of [Web sites]. Microsoft tried to do that. Unless you can do that, there's no guarantee you're not going to be fooled.
IDG News Service: How do we train our brains to be more perceptive?
Schneier: Experience. Understanding the threats.
IDG News Service: So what do you think is the biggest threat right now?
Schneier: Crime.
IDG News Service: So how do you fix it? It's expensive to investigate, it's cross-jurisdictional.
Get the independent advice and expertise you need to support a virtual workforce.
The increase in Linux popularity has increased the frequency and sophistication of malware attacks. Read this 2 page white paper now to learn how you can protect your Linux environment with real-time protection that is certified by all major Linux vendors.
Download now »Ensuring acceptable application delivery will become even more difficult over the next few years. As a result, IT organizations need to ensure that the approach that they take to resolving the current application delivery challenges can scale to support the emerging challenges. This handbook elaborates on the key tasks associated with planning, optimization, management and control and provides decision criteria to help IT organizations choose appropriate solutions.
Download now »A common misconception is that mid-range storage requirements are dramatically different than that of a larger enterprise. Mid-range storage users may require less capacity, but they have similar functionality and management requirements. This ESG paper examines mid-range storage needs and reviews a new solution that adjusts size while retaining value, performance and functionality.
Download now »
Sign up to receive Security Resource Alerts
This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.
Download now! »Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.
Download now! »Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.
Download now! »