Slashdot Mirror


Security Alert

jnazario writes "As a computer security professional, one of the things I notice is that for our proposals to be effective, they often require the participation of the vast majority of computer users out there. Almost all of them are not computer security professionals, so it's imperative that our methods be usable by the non-professionals. What makes this even worse is that most computer users are not terribly savvy about what they're using. Terms like hard drives and memory don't mean anything to them, and a browser is just a window to the internet. A computer is a tool for information use, not an end in itself. So, a book like Security Alert: Stories of Real People Protecting Themselves from Identity Theft, Scams and Viruses sounded like it had real promise." Read on for Nazario's review of the book. Security Alert: Stories of Real People Protecting Themselves from Identity Theft, Scams and Viruses author Becky Worley pages 266 publisher Pearson Education rating 3/10 reviewer Jose Nazario ISBN 0735713529 summary Real world tips for regular people to protect themselvs online

If it can communicate threats and solutions effectively to the average computer user, then we're making real progress. After all, even computer security professionals often fail to employ basic measures to protect themselves from typical attacks, we'll have to make sure this stuff is understandable by the general population. Not that they're the "great unwashed" -- hardly. They're just not focusing on this stuff. Hence, we have a challenge: make this stuff understandable by your mom if you want everyone to just get it.

Becky Worley is (was? I haven't watched TechTV in a while) a TechTV on-air personality. She's reported news and events for TechTV for a number of years, and has often done so clearly and at a level you'd expect for a general TV station devoted to technology issues. So, you'd think she'd be a in a great position to collect information and know how to present it. Sadly, Worley's book doesn't fit that niche; it's not going to educate the large masses. In putting myself in the shoes of an average computer user, I found it fails in a number of ways.

The first and foremost failure of the book is right from the beginning. Worley opens up by saying that you're not a target of hackers, yet the rest of the book goes on to discuss how you are. While you're probably not going to be attacked by the same people who try and break in to Pentagon computer networks, virus writers and con artists fall into the same category for most purposes. All of these sorts of people, and what they can do, is described in chapter 1.

There's no discussion of phishing in the chapter on identity theft, which is chapter 2. Identity theft is a large, complicated subject, yet Worley only focuses on credit card number theft. While she talks about social security numbers, she doesn't demonstrate how they have been used to destroy victims' lives. Some advice is given as to how to react to credit card theft, but little information is given here about how to protect yourself to begin with, aside from being careful about whom you give your SSN to.

The book repeats itself often, covering similar material in several places. Chapter 3, which covers online purchasing, covers credit card info theft and email scams again. What it doesn't cover very well is how to spot a legitimate website, how to really use an escrow service, if and how you can get eBay or a shipper to help you out of a scam auction, and the like. Useful information about verifying who owns a certificate for an SSL server, or even making sure you're using an SSL server, is not given. Examples of false websites and auctions would have been useful. After all, after telling us how scammers operate and look so legitimate, illustrating the points about how to spot them would be valuable.

The book is full of anecdotes but few useful pieces of information are placed where they need to be. Chapter 4, which covers viruses, is one of these examples. It spends most of its time covering typical viruses and the usual, but doesn't get into anything beyond "use antivirus software." Never mind that the biggest threat in recent years has been from automated worms and that personal firewalls are useful; that's covered later. We hope you remember the quick tutorial on viruses from before.

The book's organization is poor, with material scattered throughout the book in a fashion that doesn't progress well or develop the information seamlessly. More virus and scam information is placd in Chapter 5, along with virus hoaxes. Several websites are refered to, but little in the way of really spotting a virus hoax or the common scam. Since they still abound, and people still fall prey to them, couldn't a better job have been done to describe what people are looking at have been offered?

In short, the book is a decent collection of links and material but is so poorly organized or so thinly presented it's hard to get what's going on. Take chapters 6 and 7, "Safe and Sane Online Interactions" and "Protecting the Family." Lots of information, somewhat poorly organized, and very skimpy on content. It seems to me that worrying about who is pestering my kids is more important than hearing about someone's EverQuest addiction, so that was a wasted page.

Finally, Chapters 8 and 9 should have been moved up front more. The topic of chapter 8, "Privacy," is perfect for the topics in chapter 2, where worley talks about identity theft. The topics covered here, including spyware and key loggers, are far more germane to the threat against your privacy and bank account information, and have been a growing trend for at least a couple of years. Chapter 9, differentiating being safe and being paranoid, should have been placed up front to help temper the arguments given in the rest of the book. It does a decent job of articulating the threats, what's to fear, and what's at stake.

The book is laden with plenty of anecdotes about online activitis gone awry. What's missing are solid examples of how to do it right, how to use your credit card on trusted sites safely and ensure that you're using services you know are worthwhile. While the book has some useful information in it, it's buried under poor organization, unclear language and presentation, and finally repetition in all the wrong places.

While the world needs a book or two to help every day people understand online security, this isn't the one. If you're looking for something for your kids, your spouse, or your parents, keep looking. This book wont help them make sense of what's going on. I don't think that's too much to ask for, especially from an organization like TechTV which has access to lots of material, people, and motive to produce a solid book.

You can purchase Security Alert: Stories of Real People Protecting Themselves from Identity Theft, Scams and Viruses from bn.com. Slashdot welcomes readers' book reviews -- to see your own review here, read the book review guidelines, then visit the submission page.

21 of 162 comments (clear)

  1. Shouldn't this be... by Anonymous Coward · · Score: 5, Insightful

    under Book Reviews?

  2. One thing.. by hookedup · · Score: 4, Insightful

    Getting people informed before their machine is infected with something is the hard part.

    I find they are a whole lot more interested in learning about security as soon as they start getting pornography popups.

    1. Re:One thing.. by Anonymous Coward · · Score: 3, Insightful

      Thats about the same as people who don't think they need data backup until that laptop hdd that they have been storing 3 years of business data on dies.

    2. Re:One thing.. by tchuladdiass · · Score: 2, Insightful

      And then they think that they are safe if they don't accept any browser cookies.

  3. Own a computer, own a car by Anonymous Coward · · Score: 5, Insightful

    I am a firm believer that if you own a car, you should be able to change a tire, and change the oil. Basic matinence.

    Same with a computer. If you own a computer, you should be able to upgrade its security, and install a virus protector (minimum!)

    I dont understand why people spend thousands of dollars on a new device, then simply dont bother to learn anything about it. A computer, like a car, is a serious investment. Learn how to use it properly.

    Of course, my theory goes to shit as many people dont know how to change a tire or oil. Oh well.

    1. Re:Own a computer, own a car by nlinecomputers · · Score: 4, Insightful
      I don't understand why people spend thousands of dollars on a new device, then simply don't bother to learn anything about it. A computer, like a car, is a serious investment. Learn how to use it properly.


      Perhaps because they don't spend THOUSANDS of dollars. They spend a few hundred maybe up to about ONE thousand dollars. Computers are cheap and thus people think they are or should be as complicated as similarly priced objects like dish washers or large screen TVs.

      It they had to pay $20,000 dollars for a computer they would learn to take better care of it. But then again I see plenty of people that abuse cars too.
      --
      Slashdot, home of supporters of free software, free music, and free speech.Except for Moderators that disagree with you.
    2. Re:Own a computer, own a car by Eberlin · · Score: 5, Insightful

      You'd get called an elitist (as I did) for suggesting the need for computer users to be competent.

      Basic computer skills are a difficult enough concept for some -- and anything past "two clicks on the blue letter E" goes over their heads. Anti-virus, firewalls, and windows update? Way too complicated. Downloading and installing another browser? That's a challenge! (I got a call once from someone who couldn't install something from CD-ROM because it wasn't set to auto-run!) Reformat a hard drive and install an alternative operating system? Definitely too much.

      There isn't any interest in knowing anything past 2 clicks on blue E. Solution? FUD 'em. (not essentially lies but fun half-truths) Tell them their machines are being constantly attacked over the net and they need to protect themselves. Teach them that their personal information can get stolen. Tell them that unless they learn the ropes, they'll have to deal with headaches and heartaches and big computer repair bills.

      Hell, tell them that without a good firewall, (Osama || Saddam || tooth fairy) will break into their computers and terrorists will win. (That method seemed to work well with the average Joe Sixpack for a different, more lethal cause).

      Either way, education is part of the solution...but you can only educate those that want to learn. The trick is to motivate people into learning and understanding computer security.

    3. Re:Own a computer, own a car by dillon_rinker · · Score: 2, Insightful

      And the battery. And the brakepads. And spark plugs. And spark plug wires. And the air filter. And the fuel filters. And check fluid levels. And refill with fluid when necessary.

      In short, people should know how to do all those things that the engineers can't do for them, since the engineers must design cars with parts that wear out.

      Another car analogy - if you put your CAR on the ROAD you must ensure that your CAR is not a danger to other CARs on the ROAD. Replace CAR with COMPUTER and ROAD with INTERNET. Granted, no one will die if you get infected with a zombie, but neither is your car capable of crashing every other car on every road in the world.

    4. Re:Own a computer, own a car by Eberlin · · Score: 2, Insightful

      A bit of hyperbole there, but anyhoo, the spirit of the post was to get people to CARE about learning. Spitting out "truth" and details on "the problems and the hows and whys" isn't interesting until you can get their attention.

      Even school has its barf-back education process. You get facts and dates and other mantras that they cram down your throat and learn to barf back during an exam. The real retained knowledge are the bits we found interesting, fun, or somehow important.

      So of course not, don't lie and scare novice computer users and then have them helplessly fend for themselves -- that's not much education. Teach...but first convince them of why the knowledge is something worth learning.

    5. Re:Own a computer, own a car by SillyNickName4me · · Score: 2, Insightful

      > PEOPLE AREN'T STUPID

      Not as individuals usually, as a group they are.

    6. Re:Own a computer, own a car by techno-vampire · · Score: 3, Insightful
      I dont understand why people spend thousands of dollars on a new device, then simply dont bother to learn anything about it. A computer, like a car, is a serious investment. Learn how to use it properly.

      Back when I was doing tech support, I heard almost daily from people who'd say, "I'm completely computer illiterate." Most of them would say it not in shame but in pride. They seemed to think there was something good about being incompotent and that it made them better than people who knew how to use computers. There are more of them out there than you'd like to think, and none of them want to know what they're doing. Same thing as it is with cars; knowing how to change a tire makes you lower-class in their eyes, just as knowing how to install software.

      --
      Good, inexpensive web hosting
  4. RTFM Issue by webword · · Score: 4, Insightful

    Unfortunately the folks who need the help the most are the the least likely to read. It is like a law: Those who need to RTFM are least likely to RTFM.

    1. Re:RTFM Issue by justkarl · · Score: 2, Insightful

      That's just the thing, though. To people like "us", issues with identity, privacy, security and the like come as a sort of intuition. But when Joe User sees a popup on his monitor that says "Click me! You're a Winner!", they say "Sweet!" and they do click on it. You and I know better, because we know what happens. But I think people need to be a little paranoid, and a lot informed about their surroundings on the internet. Then it makes our jobs easier.

  5. In real life by Otter · · Score: 4, Insightful

    Every society develops certain universally-known rules of thumb about safety, from "Don't swim in the muddy water near that rivermouth!" to "Stay clear of the bar where all the tweaker bikers hang out!" Eventually, we'll have universal wisdom about being careful of email attachments and avoiding phishing schemes. But it'll have to happen through word of mouth and Oprah. No one is going to read a book like this.

  6. Did my paradigm shift? by mreed911 · · Score: 1, Insightful

    So let me get this straight:

    I'm supposed to buy a book that I've never seen nor heard of before, judge it by it's cover and it's self-aggrandizing description, then open it and proceed to upload it into my brain without any virus scan for all the tinfoil-hat type text.

    Then, this book will tell me that I shouldn't do on the internet, in email, etc. what they're absolutely counting on me doing in real life? I can't trust those emails and open those attachments and download the contents because it's unsafe?

    I think I'm going to go write an antivirus book that everyone must buy before they read any more books, and sell a service where people can't read books unless I've read them first and deemed them safe. And oh, yeah, you'll have to buy the update to my book every few days as I read new books.

  7. Not all problems are solvable by flinxmeister · · Score: 4, Insightful

    The systems of today are designed to be usable by the average Joe and Jane, but they aren't designed to be securable by that constituency.

    From a security perspective, "computers these days" are like a nuclear reactor, or a rocket, or the tax code. They're just not manageable by the average person, and the bolt on shells of security that are offered only work to a point. Without a consumer-securable security model integrated from the ground up, you're going to have melt downs, misfires, and botched returns.

    So, a book of anecdotes about "real people" and contemporary information security is almost going to be inherently uninformative. How could you possibly cover all the seams that todays severely limited security models leave open?

  8. General Security by starseeker · · Score: 4, Insightful

    I suspect we will never have universal security in the computer world, as long as it takes any effort on the part of the end user. Which leads to several conclusions:

    a) Social Engineering will ALWAYS succeed. Whatever engineers do to protect a computer, they can only protect the user from themselves up to a point. There's no cure for giving someone you think you trust your username and password, for example, and then having them rip of your confidential data. Or for that matter, keeping people from answering emails using information they shouldn't. It's a grim conclusion, but short of warning people not to be trusting nothing can be done.

    b) The machine itself CAN be made much more secure by default. This usually comes at the cost of user-friendlyness, but the username/password/account idea seems to be virtually universal now. The key to making a user friendly secure machine for the average consumer is to set up rules that allow the machine to do everything the user is likely to want to do, and ONLY that. In other words, some form of Mandatory Access Control. This is a pain in the neck for those who want to do lots of complex things on their machine, but I suspect the average needs of the modern user are becoming well defined enough to achieve something. And if applications AS PART OF THE DEVELOPMENT PROCESS create rules for what their program needs to be allowed to do (which can be externally audited to keep them honest) we might achieve a situation where it's difficult to impossible for a computer to be cracked from the outside through technological means.

    c) The bad news is, there's no market for b) and so it's unlikely it will ever happen. People have to be willing to pay the price for security, and I suspect up front cost of inconvenience (either to developers, end users, or both) will be seen as greater than the statistical potential of dangerous information theft. Whether that's true or not I don't know, certainly it varies on an individual level, but it takes herds of users to fund commercial software development and I suspect the average consumer response will be the immediate path of least inconvenience.

    d) Open Source, being outside normal economic constraints, might produce something like b) eventually. But while individual projects might code to such standards, they are probably too high a median to set for casual, unpaid development. Success would require most of the open source community to be willing to do extensive testing and planning for running their software in a MAC environment, and that's not much fun to most non-security oriented developers.

    e) So, in the end, matters will only improve when the costs of electronic theft and attack are so high they raise demand for secure systems to the economic minimum. Whether that will ever happen I don't know. My cynical guess is it won't - we'll just have to live with it. (Individual geeks of course can try to do better, but the internet has become a community. For better or worse.)

    --
    "I object to doing things that computers can do." -- Olin Shivers, lispers.org
  9. Skip the technical details by rufey · · Score: 2, Insightful
    I just spent the past few days with my spare time cleaning up a friend's computer. It was a mess with spyware/adware and possibly some maleware.

    The advice I gave them is to never download anything from the Internet that seems "cool" or promises "this or that". Sure if you are downloading an update to software you already use, its okay. But you don't need this new cool search bar for IE, a search tool that promises to be intelligent and show (a.k.a. pop-ups) only ads you'd be interested in, and you don't need to keep up with the Jones with every "cool" spyware software.

    Explaining how these things are dangerous has little affect on the "normal" computer user who doesn't know the difference between a DSL/cable router and a hub, who doesn't know how the Internet works (such as how TCP works, packets, routing).

    I've found that simply telling them to not do it is the most effecitve thing I can do. Most users won't understand the technical details. But they will understand if you simply say to not download it because if you do it enough, your computer will become unusable.

  10. sorry, not needed... by Chuck+Bucket · · Score: 3, Insightful

    Most Windows admins I know have the book "What you don't know can't hurt you", and they seem to follow that to the letter.

    CB!

  11. Perhaps. by nlinecomputers · · Score: 2, Insightful

    However it seems like to me that the average computer user 10 years ago was more knowledgeable then one is today.

    I too believe in the grand parents argument. People should have a minimum knowledge of a computer just as they have a minimum knowledge on how to run a car.

    Actually a lot of people couldn't change a tire if there life depended on it. But they can look at a tire and note that it is low and they will have tires rotated and inspected on a regular basis. Something that computer users will not do.

    --
    Slashdot, home of supporters of free software, free music, and free speech.Except for Moderators that disagree with you.
  12. Re:I know nothing about computers. Take care of me by random_static · · Score: 2, Insightful
    this will only work if the same user is willing to accept "i can't let you download that junk / play that game / view that malware-laden web page" when the machine tells them so.

    making a machine that won't get infected by all kinds of crap isn't all that hard; making a machine that won't get infected no matter what the user demands it do for them is impossible. and no user too stupid to take care of themselves is smart enough to accept being baby-sat by any mere machine.