CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer
image Editorials: Not a LaGrande Security Plan image
General News
By Tiernan Ray
www.EcommerceTimes.com,
Part of the NewsFactor Network
April 24, 2003


"The most common security problems have a human element that is not well served by innovations at a chip or operating system level -- at least, not in the way Microsoft and Intel are proposing. Sensitive documents are printed out and left lying around. Passwords are cracked because someone used their birth date rather than a random string of alphanumeric characters. Moldy, rotting floppy disks brought into the office infect first one, then many PCs with the latest virus because proper protection tools were not run. Small business Web sites are compromised and exploited as jumping-off points for denial-of-service attacks because the proprietors of those businesses have bandwidth but lack the necessary security tools to protect it."


It would be nice, though ultimately very silly, to think that the world's computing facilities could be secured by locking down the technology and ignoring the human factors. But that is what Microsoft (Nasdaq: MSFT) and Intel (Nasdaq: INTC) seem to believe, with a chip encryption technology in development at Intel called LaGrande, and a forthcoming suite of security software and hardware from Microsoft dubbed Palladium.

Of course, there is nothing wrong with making computing technology more reliable. Security, however, starts with user awareness and a policy planned and implemented by a CIO, not with the dictates of platform vendors. LaGrande and Palladium will confuse users more than help them.

To Err Is Human

The most common security problems have a human element that is not well served by innovations at a chip or operating system level -- at least, not in the way Microsoft and Intel are proposing. Sensitive documents are printed out and left lying around. Passwords are cracked because someone used their birth date rather than a random string of alphanumeric characters. Moldy, rotting floppy disks brought into the office infect first one, then many PCs with the latest virus because proper protection tools were not run. Small business Web sites are compromised and exploited as jumping-off points for denial-of-service attacks because the proprietors of those businesses have bandwidth but lack the necessary security tools to protect it.

The solution, in the view of such vendors as Intel, is simply to put the technology in place and let users know it is working for them behind the scenes. For example, LaGrande supposedly would encrypt secure sockets layer (SSL) sessions at a chip level so that mischievous types could not snoop on personal information being transmitted to a shopping Web site, for example.

However, if individuals are already clueless about Web site authentication procedures -- and they are -- how well will they deal with an additional layer of complexity involving encryption? If this is a confusing matter for individuals, it could be a nightmare for CIOs. Imagine someone trying to manage fleets of PCs if some users have encrypted part of their hard drive to protect their vital data. You have a Mexican standoff waiting to happen.

I Know What You Downloaded Last Night

Security has to be a CIO priority, and there must be a clear plan to achieve it. These issues cannot be addressed by hiding or burying encryption and passcodes within PC hardware. Efforts like LaGrande and Palladium would create exactly what CIOs do not need -- non-portable black boxes, ill-understood except by vendors, that are unevenly deployed across a mix of hardware and software.

For the same reason, the technology will fail in the area of rights management for digital media, which, despite all the talk of protecting users, is just as much a priority for Microsoft, Intel and their media partners. Any security on digital media is a contract between media consumers and media providers. Telling consumers that their computer has a secret contract with a media vendor negotiated behind their backs is a quick route to confusion and frustration, not copyright protection.


Source: News Factor
Posted on Thursday, 24 April 2003 @ 14:23:07 UTC by cj (937 reads)
[ Trackback ]
image

"Editorials: Not a LaGrande Security Plan" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· Microsoft
· Intel
· HotScripts
· W3 Consortium
· More about General News
· News by cj


Most read story about General News:
Weekly Spyware Alert: CoolWebSearch

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer