- TrueColor Tech: Calgary Computer Services
- IRC Mini-How-To
- Svchost Memory Hog Fix
- Uninstalling Programs You Can't Seem to Get Rid Of
- Windows Xp Clean Install
- Five Command Line Tools to Detect Windows Intrusion
- We Take Used/Junk Hardware
- Computer Forensic Training - How To Become a Computer Forensics Investigator
- Multiple Computers One Mouse and Keyboard
- Computer Repair Service - Are You Being Conned?
- Common Troubleshooting Steps DLL Errors
- Slow Brute Force Attacks
- Spyware Removal - A Simple Approach
- Get Your Own Website or Blog - Calgary Web Design
- PC Error Prevention Tips
- DNS Forgery
- 10 Things To Do
- Quality Hosting Services - UDSHELLS
- Vulnerability Assessment With Nessus and Ntop
- SSH Tunneling
- 10 Things Your IT Guy Wants You To Know
- Desktop Computers Cheap - Wholesale Laptops
- Become a Software God
- Tips For Dealing With DLL Issues
- Unix And Internet Fundamentals
- Windows 7 RC Review
- Solving DLL Errors Related To Malware
- Robust IPTABLES Firewall
- Crash Course In Computer Hardware
- The Six Dumbest Ideas in Computer Security
- Dealing With DLL Application Errors
- How I Would Hack Your Weak Passwords
- I Bought a New Computer, What Should I Do With The Old One?
- 10 Mistakes New Linux Administrators Make
- Linux: Stop Holding Our Children Back
- Online Backup Services - A Simple Guide
- Desktop Computers Cheap - Wholesale Laptops
- Crash Course In Computer Hardware
- Tips For Dealing With DLL Issues
- Solving DLL Errors Related To Malware
- TrueColor Tech: Calgary Computer Services
- Become a Software God
- Get Your Own Website or Blog - Calgary Web Design
- Dealing With DLL Application Errors
- Multiple Computers One Mouse and Keyboard
- Robust IPTABLES Firewall
- Windows 7 RC Review
- Online Backup Services - A Simple Guide
- Computer Forensic Training - How To Become a Computer Forensics Investigator
- IRC Mini-How-To
- I Bought a New Computer, What Should I Do With The Old One?
- SSH Tunneling
- The Six Dumbest Ideas in Computer Security
- PC Error Prevention Tips
- Quality Hosting Services - UDSHELLS
- How I Would Hack Your Weak Passwords
- Linux: Stop Holding Our Children Back
- Slow Brute Force Attacks
- 10 Mistakes New Linux Administrators Make
- 10 Things Your IT Guy Wants You To Know
- Vulnerability Assessment With Nessus and Ntop
- Svchost Memory Hog Fix
- Spyware Removal - A Simple Approach
- DNS Forgery
- Five Command Line Tools to Detect Windows Intrusion
- Uninstalling Programs You Can't Seem to Get Rid Of
- Common Troubleshooting Steps DLL Errors
- We Take Used/Junk Hardware
- Computer Repair Service - Are You Being Conned?
- 10 Things To Do
- Unix And Internet Fundamentals
- Windows Xp Clean Install
The Six Dumbest Ideas in Computer Security
The Six Dumbest Ideas in Computer Security
There's lots of innovation going on in security - we're inundated with a steady stream of new stuff and it all sounds like it works just great. Every couple of months I'm invited to a new computer security conference, or I'm asked to write a foreword for a new computer security book. And, thanks to the fact that it's a topic of public concern and a "safe issue" for politicians, we can expect a flood of computer security-related legislation from lawmakers. So: computer security is definitely still a "hot topic." But why are we spending all this time and money and still having problems?
Let me introduce you to the six dumbest ideas in computer security. What are they? They're the anti-good ideas. They're the braindamage that makes your $100,000 ASIC-based turbo-stateful packet-mulching firewall transparent to hackers. Where do anti-good ideas come from? They come from misguided attempts to do the impossible - which is another way of saying "trying to ignore reality." Frequently those misguided attempts are sincere efforts by well-meaning people or companies who just don't fully understand the situation, but other times it's just a bunch of savvy entrepreneurs with a well-marketed piece of junk they're selling to make a fast buck. In either case, these dumb ideas are the fundamental reason(s) why all that money you spend on information security is going to be wasted, unless you somehow manage to avoid them.
For your convenience, I've listed the dumb ideas in descending order from the most-frequently-seen. If you can avoid falling into the the trap of the first three, you're among the few true computer security elite.
Last Updated (Thursday, 24 September 2009 02:29)
|
