Feeds

Intel reveals 'the billion dollar lost laptop problem'

Chipzilla's plan to rescue $bns spent on McAfee

SANS - Survey on application security programs

Squirrelly users

Users came in for their share of blame, as well. Ponemon said those worthies often muck about with IT-installed security measures: "Even things like encryption, for example — file encryption, not whole-disk encryption — it's pretty easy to turn it off. And a lot of end users are saying, 'How can I circumvent the security system? My booting up everyday, it's another 10 seconds — or the degradation is a nanosecond — I don't want to live with that.'

"So the company thinks everything's okay," he said, "but the end user is really carrying a loaded gun."

But users' lackadaisical attitude is easily understood, said Ponemon: "For the most part end users aren't security people, and they don't care about security, and they see it as an incovenience."

The solution — and here's where Intel's "third pillar" comes in — is to make laptop security a no-brainer. "The more you can 'idiot proof' — excuse that statement — or make it easy or invisible to the user," Ponemon said, "the more successful you're going to be."

Beaver think that hardware-based security is inevitable. "It might be next year, it might be five or 10 years from now, but I do think there will be a general expectation from people across the board, like 'Hey you, Mr. Hardware Vendor, what are you doing to protect my data?'"

Despite the clear connection of the panel's message to Intel's McAfee aquisition, Beaver was the only panelist to mention it, even in passing:

One of the things I've always said is that unless and until the hardware vendors implement security at that level — in the factory — I think we're going to continue having data-security probllems. Be it something like anti-theft technology ... [or] something related to an acquisition recently, I think that is going to help facilitate a lot of security and help fulfill a lot of exectations down the road.

Pashupathy may not have spoken directly about Intel's third pillar, but he did wax rhapsodically about the promise of hardware-based laptop security: "Our goal — at least my product's goal — is to embed [security] in hardware, and build out an ecosystem such that it does become a standard over time. It's not a standard today, but that would be nirvana." ®

Bootnote

Ponemon also spoke of one immediate and low-tech way to increase the security of your company's laptops: "Some companies now require you to put a label, a company label, like 'I work for Accenture'," onto employees' laptops, he said. "It's probably a bad idea to do that, even though it might make it easier for you to say, 'That is my Dell,' and not somebody else's and by accident take someone's computer that looks the same. But it may, in fact, increase the risk of theft, and we have some early evidence that suggests that."

Combat fraud and increase customer satisfaction

More from The Register

next story
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
prev story

Whitepapers

Designing a defence for mobile apps
In this whitepaper learn the various considerations for defending mobile applications; from the mobile application architecture itself to the myriad testing technologies needed to properly assess mobile applications risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.