Feeds

Gartner lambasts security FUDmongers

Get a grip, analyst rants

  • alert
  • submit to reddit

Protecting against web application threats using SSL

Some organisations are holding back on the deployment of new technologies because of exaggerated IT security risks, according to Gartner. The analyst firm took aim at what it identified as the five most over-hyped threats at the end of a three-day IT security conference at its Stanford, Connecticut HQ, this week.

According to Gartner, the five most over-hyped security threats are:

  • Internet Protocol (IP) telephony is unsafe
  • Mobile malware will cause widespread damage
  • "Warhol Worms" will make the Internet unreliable for business traffic and virtual private networks (VPNs)
  • Regulatory compliance equals security
  • Wireless hot spots are unsafe

"Many businesses are delaying rolling out high productivity technologies, such as wireless local area networks (WLANs) and IP telephony systems because they have seen so much hype about potential threats," said Lawrence Orans, principal analyst at Gartner.

Gartner analysts singled out the ideas that IP Telephony is unsafe and that mobile malware will be a big problem for particular scorn.

"The reality is that security attacks are rare for IP telephony. Preventive measures for securing an IP telephony environment are very similar to securing a data-only environment. IP telephony eavesdropping is the most over-hyped threat. Eavesdropping is unlikely to happen since it requires local area network (LAN)-based access to the intranet," it said. And besides which firms can always encrypt traffic.

Mobile malware risks were dismissed as a "niche nuisance" in the foreseeable future if for no other reason than penetration of smartphone and personal digital assistants (PDAs) with always-on wireless capabilities remains low.

"Anti-virus vendors see huge potential profit opportunities in selling security solutions to billions of cell phone and PDA users," John Pescatore, vice president said. "In particular, the anti-viral industry sees cell phones as the way to grow sales outside of a flat, commoditized PC market. However, device-side anti-viruses for cell phones will be completely ineffective. The most effective approach to blocking mobile malware will be to block it in the network," he added.

In the past Gartner has been vocal about corporate wireless security issues in particular but like us they've probably had their fill of talk of Evil Twin threats and the like so we can excuse them for letting off steam. It's pretty well known that fear pushes security sales but over recent months the trend of vendors talking up real or perceived security risks has became more pronounced and tiresome than ever. Think of a threat real or imagined (phishing, pharming, Evil Twin Wi-Fi hotspots, hackers taking over the national grid, Bluesnarfing etc. etc. ad nauseam) and it only a matter of days or week before vendors tout "silver-bullet" security solutions. Gartner's rant represents a welcome reality check against that onslaught.

However one question remains: what have the anti-virus vendors done to upset Pescatore so much? How else to explain his (admittedly entertaining) diatribe? ®

Related stories

Users untouched by mobile viruses despite hype
Beware the rogue access points, says Gartner
Corporate governance goals impossible - RSA
Net survives mass-defacement contest
Soon al-Qaeda will kill you on the Internet

Reducing the cost and complexity of web vulnerability management

More from The Register

next story
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
TOR users become FBI's No.1 hacking target after legal power grab
Be afeared, me hearties, these scoundrels be spying our signals
Jihadi terrorists DIDN'T encrypt their comms 'cos of Snowden leaks
Intel bods' analysis concludes 'no significant change' after whistle was blown
Home Depot: 56 million bank cards pwned by malware in our tills
That's about 50 per cent bigger than the Target tills mega-hack
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
China hacked US Army transport orgs TWENTY TIMES in ONE YEAR
FBI et al knew of nine hacks - but didn't tell TRANSCOM
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.