Feeds

Gartner lambasts security FUDmongers

Get a grip, analyst rants

  • alert
  • submit to reddit

Top three mobile application threats

Some organisations are holding back on the deployment of new technologies because of exaggerated IT security risks, according to Gartner. The analyst firm took aim at what it identified as the five most over-hyped threats at the end of a three-day IT security conference at its Stanford, Connecticut HQ, this week.

According to Gartner, the five most over-hyped security threats are:

  • Internet Protocol (IP) telephony is unsafe
  • Mobile malware will cause widespread damage
  • "Warhol Worms" will make the Internet unreliable for business traffic and virtual private networks (VPNs)
  • Regulatory compliance equals security
  • Wireless hot spots are unsafe

"Many businesses are delaying rolling out high productivity technologies, such as wireless local area networks (WLANs) and IP telephony systems because they have seen so much hype about potential threats," said Lawrence Orans, principal analyst at Gartner.

Gartner analysts singled out the ideas that IP Telephony is unsafe and that mobile malware will be a big problem for particular scorn.

"The reality is that security attacks are rare for IP telephony. Preventive measures for securing an IP telephony environment are very similar to securing a data-only environment. IP telephony eavesdropping is the most over-hyped threat. Eavesdropping is unlikely to happen since it requires local area network (LAN)-based access to the intranet," it said. And besides which firms can always encrypt traffic.

Mobile malware risks were dismissed as a "niche nuisance" in the foreseeable future if for no other reason than penetration of smartphone and personal digital assistants (PDAs) with always-on wireless capabilities remains low.

"Anti-virus vendors see huge potential profit opportunities in selling security solutions to billions of cell phone and PDA users," John Pescatore, vice president said. "In particular, the anti-viral industry sees cell phones as the way to grow sales outside of a flat, commoditized PC market. However, device-side anti-viruses for cell phones will be completely ineffective. The most effective approach to blocking mobile malware will be to block it in the network," he added.

In the past Gartner has been vocal about corporate wireless security issues in particular but like us they've probably had their fill of talk of Evil Twin threats and the like so we can excuse them for letting off steam. It's pretty well known that fear pushes security sales but over recent months the trend of vendors talking up real or perceived security risks has became more pronounced and tiresome than ever. Think of a threat real or imagined (phishing, pharming, Evil Twin Wi-Fi hotspots, hackers taking over the national grid, Bluesnarfing etc. etc. ad nauseam) and it only a matter of days or week before vendors tout "silver-bullet" security solutions. Gartner's rant represents a welcome reality check against that onslaught.

However one question remains: what have the anti-virus vendors done to upset Pescatore so much? How else to explain his (admittedly entertaining) diatribe? ®

Related stories

Users untouched by mobile viruses despite hype
Beware the rogue access points, says Gartner
Corporate governance goals impossible - RSA
Net survives mass-defacement contest
Soon al-Qaeda will kill you on the Internet

Combat fraud and increase customer satisfaction

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Canadian taxman says hundreds pierced by Heartbleed SSL skewer
900 social insurance numbers nicked, says revenue watchman
German space centre endures cyber attack
Chinese code retrieved but NSA hack not ruled out
Burnt out on patches this month? Oracle's got 104 MORE fixes for you
Mass patch for issues across its software catalog
Reddit users discover iOS malware threat
'Unflod Baby Panda' looks to snatch Apple IDs
Oracle working on at least 13 Heartbleed fixes
Big Red's cloud is safe and Oracle Linux 6 has been patched, but Java has some issues
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.