Free Newsletters
InfoWorld Daily

InfoWorld
Log-in | Register
SECURITY ADVISER  

Hackers keep hacking because they can

Point-solution security products miss the underlying reason for poor security: lack of authentication

By Roger A. Grimes
June 23, 2006
 

I had yet another computer journalist call me to ask if Vendor X’s security solution was THE security product to solve all our security problems. I get a call or e-mail like this about once every two weeks. Usually they’ve read the vendor’s own PR, another newspaper article, or even my own column touting a particular product. The typical conversation goes something like this:

Free IT resource

Virtualization Insights from Top Experts - Learn how virtualization gets real!

Sponsored by Dell

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

Journalist: "Hey, do you think Product A from Vendor X will solve all our security problems?" (I’m not making up this question, either -- I hear a version of it 99 percent of the time.)

Me: "No, I think security is only going to get worse and every proposed product is doomed to failure. I predict that within a few days the Internet will collapse and online communication as we know it will cease to exist and the Internet will have to be rebuilt from the ashes over the next six months. On the positive side, we’ll all have a lot more time for our family soon."

Journalist: [Silence or pause] “Huh?”

To be fair, a little more than half of them know I’m pulling their leg. Only a few formally ask if they can quote me.

It bothers me that a lot of computer security journalists don’t really know security. Not that I’m an expert, but when a vendor’s press release starts out with the phrase, “We detect all threats known and unknown, without frequent updates," I immediately discount that product.

Usually I end up explaining to the journalist how none of the security products we use will ever be perfect because they are all point solutions ignoring the real problem: Most hackers and malware spreaders never get caught. If hackers and malware writers knew we could catch them most of the time, we wouldn’t even need anti-virus software or firewalls, because our security threats would be almost gone.

This is analogous to speeding on the highway. Nearly everyone speeds on the highway because few speeders get caught. But if every speeder got a ticket every time (think ticket-cams), you’d see all drivers slow down.

The real computer security problem is a lack of persuasive authentication. If the Internet allowed default authentication and accountability for every packet and every program, from source to destination, hacking and malware would stop overnight. In a better world, if someone sent me a malicious program, I could track it back not only who sent the program to me, but who sent the program to them, and so on … back to the original creator, with nearly 100 percent certainty. Hacking would cease to exist.

It’s not as if this idea is unknown to the world. Many security solutions attempt to tackle authentication: PKI, S/MIME, PGP, ActiveX, smart cards, network access control solutions, etc. But each of these is only point a solution, tackling a particular part of the problem but not every possible scenario.

Lots of people are trying to build a holistic solution, but persuasive authentication isn’t easy or fast to accomplish. The Trusted Computing Group’s open standards are a good place to start. They offer guidance to computer device manufacturers and software developers attempting to build in default trust and authentication.

The idea is that everything needs to be authenticated, including the hardware, operating system, application software, and anything the software creates or sends. It all starts with trusted hardware components, to prevent software from manipulating and invalidating the trust routines situated in the hardware. Currently, many hardware and CPU vendors are building TPM (trusted platform module) chips onto the motherboard. Linux and Microsoft are already starting to use the chips; enterprise versions of Windows Vista will use the TPM chips to store encryption keys that lock up the hard drive prior to booting to prevent boot-around attacks.

Once the hardware is secure, vendors can build trusted and authenticated operating systems that rely on the trusted hardware. Then application vendors can rely on the OS for trust and allow people to send trusted data content back and forth to each other.

In the future, it is highly likely that the Internet Version 2 will require default authentication on all messages, from source to destination. For example, in order for your e-mail server to send an e-mail to my e-mail server, it must authenticate to my e-mail server first. Your e-mail server will authenticate that your e-mail came from you and that you meant to send it. Your operating system will ensure that your e-mail client isn’t being controlled by a worm or spybot.

Some people say that persuasive authentication is bad, that anonymity is necessary in certain places, like AIDS testing organizations and rape recovery meeting groups. That's fine -- keep your anonymity. I’ll just not allow anything that needs anonymity to connect to my business asset, and I’ll pay extra for that protection.

Maybe there will be two Internets: one for default authentication (and encryption) and another for the untrusted world to play. IRC (Internet Relay Chat) channels have that now. Communicating on unauthenticated IRC chat channels is a dangerous place to hang out for most Internet users. The trusted and authenticated IRC chat channels are mostly free of malicious hacking and bot wars that plague the untrusted version.

For hackers to attack the trusted Internet, they will need to compromise the persuasive authentication mechanisms. And they will, because humans will code the authentication mechanisms and we are imperfect. But we will be able to install one patch and immediately remove that attack threat -- which is the opposite of what we do now. Today, we cure one symptom while ignoring the underlying disease.

The solution to our security problems isn’t a particular product or vendor, but persuasive authentication, which will probably only happen after multiple catastrophic e-commerce events and forced government regulation. We know what the fix is, but we are reactive sheep, waiting to be forced to the real solution.





 


 
InfoWorld Test Center Contributing Editor Roger A. Grimes is a Foundstone Ultimate Hacking instructor/consultant teaching Windows, Linux, Unix, and Solaris security.

  More of Roger A. Grimes' column

Newsletter Check out all of our free newsletters!
Enter e-mail address:




 

TOP NEWS:


»  Four quick tips for choosing an IM security product
71 percent of businesses will invest in real-time messaging this year. If you're one of them, be sure to protect your enterprise

»  Forrester analysts ID hot IT jobs
Research group finds 16 IT roles with a promising future

»  Nvidia claims 10 hours of HD video on Tegra chip
The Tegra 600 and 650 can be used with hard disk drives and are designed partly for mobile Internet devices

»  Database vendors add Google's MapReduce
Greenplum and Aster Data Systems will support Google's programming technique, developed for parallel processing of large data sets across commodity hardware

»  Network management: Tips for managing costs
New technologies, changing requirements, and ongoing equipment maintenance and upgrades cost money, but there are ways to manage expenses

»  EMC targets SMBs, branch offices with new low-end storage
Celerra NX4 highlights include thin provisioning, snapshot technology for data recovery and backups, and Web-based console for management of storage volumes




COMPREHENSIVE DATA PROTECTION AND DISASTER RECOVERY
Traditional backup and recovery is becoming irrelevant. You need more. Watch this InfoWorld and Dell Equallogic webcast to learn the current trends in Comprehensive Data Protection and Disaster Recovery for VMware Virtual Infrastructure. Sponsored by Dell Equallogic:

»  Click here to view this Webcast
  Protection for Remote Sites and Branch Offices
This Whitepaper reviews the challenges of creating appropriate data protection, especially for small and midsize companies with remote and branch offices. It offers suggestions on how you can choose the most appropriate data protection solution for your company's needs. Sponsored by Overland

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 

FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE



TECHNOLOGY INDEX
• Applications
• Application Development
• Security
• Networking
• Wireless
• Platforms
• Hardware
• Data Management
• Storage
• Web Services
• Business
• Telecom
• Professional Services
• Standards

TECH WATCH 


What's the 411 on GOOG-411?
Just as Google has become synonymous with "performing a Web search," 411 is understood to mean "information" -- as in "what's the 411?" I was thus surprised to discover, from a billboard, no less, that the king of search is taking on the ...

Apple HTML source reveals 'iPhone Extreme'
"This one's a stretch..." reports AppleInsider. Um, yeah. Reporting on HTML code sightings of product names could be called a stretch, but iPhone Extreme has a ring to it. Now, that sounds like the product Apple should have released first, rather ...

COLUMNISTS

Unified under law
Ephraim Schwartz's Column and Blog (InfoWorld) - In the litigious world we live in, deploying a unified communications platform in your enterprise could...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Open Sources 
Product Management
When I joined MySQL four years ago, there was quite a lot of debate about product management. We didn't actually have ...

Zero Day 
Botnet herders tending smaller flocks
New research backs up the theory that botnet operators are keeping their networks smaller in a continued effort to keep ...



• Advice Line
• Database Underground
• The Deep End
• Enterprise Mac
• Geeks in Paradise
• Grid Meter
• The Gripe Line
• InfoWorld Daily
• Inside IT
• IT Troubleshooter
• ITXtreme
• Open Sources
• ProdBlog
• Real World SOA
• Reality Check
• Security Adviser
• SMB IT
• The Storage Network
• Tech Watch
• Virtualization Report
• Zero Day

ADVERTISEMENT


RESOURCE CENTERadvertisement 

GOVERNMENT IT & POLICY
'If you don't go after the network, you're never going to stop these guys. Never.'
From the State Department, All the News for Inquiring Minds
TechPresident, the Internet Citizenry's New Consensus Taker



Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist
TecChannel :: TecCommunity