Feeds

Bad security products thrive on confusion

High-drama obscures real risks, warns Schneier

Protecting against web application threats using SSL

The information security market is riddled with mediocre products because buyers are often sold on a story rather than having enough information to make a rational choice, a security expert has said.

Bruce Schneier, founder and chief technical officer of BT Counterpane, said many security products offered the feeling of being secure rather than actual security. Vendors can't be trusted to give a reliable precis of a product's capabilities, he warned.

The field of information technology security is so complex that purchasing decisions are based on feelings and hunches rather than reality, a process that suppliers play into, in what Schneier described as "security theatre". Products sold through this process often either fail to live up to their promises or address a threat that is overstated.

"For every supplier with a good product or service, there is at least one more out to make a quick buck before customers find out," Schneier told delegates to the RSA security conference during a keynote presentation on Tuesday. "There's a problem when feelings and reality are out of whack."

The presence of bad products diminishes trust in the market as a whole over the long-term, while leaving end-users with a false sense of security.

The same problem can apply to product categories as well as individual items of kit. Firewalls, for example, are ubiquitious but often poorly configured. On the other hand, email security products work well but enjoy little market penetration, Schneier said.

Part of the difficulty is that human beings are inherently irrational, finding it difficult to weigh a balance between risks and costs and behaving irrationally on the basis of perceived fears. "The human brain is still in beta testing. There are all sorts of patches and workarounds in there," Schneier joked. ®

Reducing the cost and complexity of web vulnerability management

More from The Register

next story
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.