Feeds

Gartner lambasts security FUDmongers

Get a grip, analyst rants

  • alert
  • submit to reddit

SANS - Survey on application security programs

Some organisations are holding back on the deployment of new technologies because of exaggerated IT security risks, according to Gartner. The analyst firm took aim at what it identified as the five most over-hyped threats at the end of a three-day IT security conference at its Stanford, Connecticut HQ, this week.

According to Gartner, the five most over-hyped security threats are:

  • Internet Protocol (IP) telephony is unsafe
  • Mobile malware will cause widespread damage
  • "Warhol Worms" will make the Internet unreliable for business traffic and virtual private networks (VPNs)
  • Regulatory compliance equals security
  • Wireless hot spots are unsafe

"Many businesses are delaying rolling out high productivity technologies, such as wireless local area networks (WLANs) and IP telephony systems because they have seen so much hype about potential threats," said Lawrence Orans, principal analyst at Gartner.

Gartner analysts singled out the ideas that IP Telephony is unsafe and that mobile malware will be a big problem for particular scorn.

"The reality is that security attacks are rare for IP telephony. Preventive measures for securing an IP telephony environment are very similar to securing a data-only environment. IP telephony eavesdropping is the most over-hyped threat. Eavesdropping is unlikely to happen since it requires local area network (LAN)-based access to the intranet," it said. And besides which firms can always encrypt traffic.

Mobile malware risks were dismissed as a "niche nuisance" in the foreseeable future if for no other reason than penetration of smartphone and personal digital assistants (PDAs) with always-on wireless capabilities remains low.

"Anti-virus vendors see huge potential profit opportunities in selling security solutions to billions of cell phone and PDA users," John Pescatore, vice president said. "In particular, the anti-viral industry sees cell phones as the way to grow sales outside of a flat, commoditized PC market. However, device-side anti-viruses for cell phones will be completely ineffective. The most effective approach to blocking mobile malware will be to block it in the network," he added.

In the past Gartner has been vocal about corporate wireless security issues in particular but like us they've probably had their fill of talk of Evil Twin threats and the like so we can excuse them for letting off steam. It's pretty well known that fear pushes security sales but over recent months the trend of vendors talking up real or perceived security risks has became more pronounced and tiresome than ever. Think of a threat real or imagined (phishing, pharming, Evil Twin Wi-Fi hotspots, hackers taking over the national grid, Bluesnarfing etc. etc. ad nauseam) and it only a matter of days or week before vendors tout "silver-bullet" security solutions. Gartner's rant represents a welcome reality check against that onslaught.

However one question remains: what have the anti-virus vendors done to upset Pescatore so much? How else to explain his (admittedly entertaining) diatribe? ®

Related stories

Users untouched by mobile viruses despite hype
Beware the rogue access points, says Gartner
Corporate governance goals impossible - RSA
Net survives mass-defacement contest
Soon al-Qaeda will kill you on the Internet

High performance access to file storage

More from The Register

next story
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
prev story

Whitepapers

Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.