Slashdot Mirror


Security Alert

jnazario writes "As a computer security professional, one of the things I notice is that for our proposals to be effective, they often require the participation of the vast majority of computer users out there. Almost all of them are not computer security professionals, so it's imperative that our methods be usable by the non-professionals. What makes this even worse is that most computer users are not terribly savvy about what they're using. Terms like hard drives and memory don't mean anything to them, and a browser is just a window to the internet. A computer is a tool for information use, not an end in itself. So, a book like Security Alert: Stories of Real People Protecting Themselves from Identity Theft, Scams and Viruses sounded like it had real promise." Read on for Nazario's review of the book. Security Alert: Stories of Real People Protecting Themselves from Identity Theft, Scams and Viruses author Becky Worley pages 266 publisher Pearson Education rating 3/10 reviewer Jose Nazario ISBN 0735713529 summary Real world tips for regular people to protect themselvs online

If it can communicate threats and solutions effectively to the average computer user, then we're making real progress. After all, even computer security professionals often fail to employ basic measures to protect themselves from typical attacks, we'll have to make sure this stuff is understandable by the general population. Not that they're the "great unwashed" -- hardly. They're just not focusing on this stuff. Hence, we have a challenge: make this stuff understandable by your mom if you want everyone to just get it.

Becky Worley is (was? I haven't watched TechTV in a while) a TechTV on-air personality. She's reported news and events for TechTV for a number of years, and has often done so clearly and at a level you'd expect for a general TV station devoted to technology issues. So, you'd think she'd be a in a great position to collect information and know how to present it. Sadly, Worley's book doesn't fit that niche; it's not going to educate the large masses. In putting myself in the shoes of an average computer user, I found it fails in a number of ways.

The first and foremost failure of the book is right from the beginning. Worley opens up by saying that you're not a target of hackers, yet the rest of the book goes on to discuss how you are. While you're probably not going to be attacked by the same people who try and break in to Pentagon computer networks, virus writers and con artists fall into the same category for most purposes. All of these sorts of people, and what they can do, is described in chapter 1.

There's no discussion of phishing in the chapter on identity theft, which is chapter 2. Identity theft is a large, complicated subject, yet Worley only focuses on credit card number theft. While she talks about social security numbers, she doesn't demonstrate how they have been used to destroy victims' lives. Some advice is given as to how to react to credit card theft, but little information is given here about how to protect yourself to begin with, aside from being careful about whom you give your SSN to.

The book repeats itself often, covering similar material in several places. Chapter 3, which covers online purchasing, covers credit card info theft and email scams again. What it doesn't cover very well is how to spot a legitimate website, how to really use an escrow service, if and how you can get eBay or a shipper to help you out of a scam auction, and the like. Useful information about verifying who owns a certificate for an SSL server, or even making sure you're using an SSL server, is not given. Examples of false websites and auctions would have been useful. After all, after telling us how scammers operate and look so legitimate, illustrating the points about how to spot them would be valuable.

The book is full of anecdotes but few useful pieces of information are placed where they need to be. Chapter 4, which covers viruses, is one of these examples. It spends most of its time covering typical viruses and the usual, but doesn't get into anything beyond "use antivirus software." Never mind that the biggest threat in recent years has been from automated worms and that personal firewalls are useful; that's covered later. We hope you remember the quick tutorial on viruses from before.

The book's organization is poor, with material scattered throughout the book in a fashion that doesn't progress well or develop the information seamlessly. More virus and scam information is placd in Chapter 5, along with virus hoaxes. Several websites are refered to, but little in the way of really spotting a virus hoax or the common scam. Since they still abound, and people still fall prey to them, couldn't a better job have been done to describe what people are looking at have been offered?

In short, the book is a decent collection of links and material but is so poorly organized or so thinly presented it's hard to get what's going on. Take chapters 6 and 7, "Safe and Sane Online Interactions" and "Protecting the Family." Lots of information, somewhat poorly organized, and very skimpy on content. It seems to me that worrying about who is pestering my kids is more important than hearing about someone's EverQuest addiction, so that was a wasted page.

Finally, Chapters 8 and 9 should have been moved up front more. The topic of chapter 8, "Privacy," is perfect for the topics in chapter 2, where worley talks about identity theft. The topics covered here, including spyware and key loggers, are far more germane to the threat against your privacy and bank account information, and have been a growing trend for at least a couple of years. Chapter 9, differentiating being safe and being paranoid, should have been placed up front to help temper the arguments given in the rest of the book. It does a decent job of articulating the threats, what's to fear, and what's at stake.

The book is laden with plenty of anecdotes about online activitis gone awry. What's missing are solid examples of how to do it right, how to use your credit card on trusted sites safely and ensure that you're using services you know are worthwhile. While the book has some useful information in it, it's buried under poor organization, unclear language and presentation, and finally repetition in all the wrong places.

While the world needs a book or two to help every day people understand online security, this isn't the one. If you're looking for something for your kids, your spouse, or your parents, keep looking. This book wont help them make sense of what's going on. I don't think that's too much to ask for, especially from an organization like TechTV which has access to lots of material, people, and motive to produce a solid book.

You can purchase Security Alert: Stories of Real People Protecting Themselves from Identity Theft, Scams and Viruses from bn.com. Slashdot welcomes readers' book reviews -- to see your own review here, read the book review guidelines, then visit the submission page.

24 of 162 comments (clear)

  1. Shouldn't this be... by Anonymous Coward · · Score: 5, Insightful

    under Book Reviews?

  2. What!?! by geomon · · Score: 4, Funny

    A computer is a tool for information use, not an end in itself.

    Blasphemy!

    Burn the heretic!

    --
    "Rocky Rococo, at your cervix!"
  3. One thing.. by hookedup · · Score: 4, Insightful

    Getting people informed before their machine is infected with something is the hard part.

    I find they are a whole lot more interested in learning about security as soon as they start getting pornography popups.

    1. Re:One thing.. by Anonymous Coward · · Score: 3, Insightful

      Thats about the same as people who don't think they need data backup until that laptop hdd that they have been storing 3 years of business data on dies.

  4. Own a computer, own a car by Anonymous Coward · · Score: 5, Insightful

    I am a firm believer that if you own a car, you should be able to change a tire, and change the oil. Basic matinence.

    Same with a computer. If you own a computer, you should be able to upgrade its security, and install a virus protector (minimum!)

    I dont understand why people spend thousands of dollars on a new device, then simply dont bother to learn anything about it. A computer, like a car, is a serious investment. Learn how to use it properly.

    Of course, my theory goes to shit as many people dont know how to change a tire or oil. Oh well.

    1. Re:Own a computer, own a car by nlinecomputers · · Score: 4, Insightful
      I don't understand why people spend thousands of dollars on a new device, then simply don't bother to learn anything about it. A computer, like a car, is a serious investment. Learn how to use it properly.


      Perhaps because they don't spend THOUSANDS of dollars. They spend a few hundred maybe up to about ONE thousand dollars. Computers are cheap and thus people think they are or should be as complicated as similarly priced objects like dish washers or large screen TVs.

      It they had to pay $20,000 dollars for a computer they would learn to take better care of it. But then again I see plenty of people that abuse cars too.
      --
      Slashdot, home of supporters of free software, free music, and free speech.Except for Moderators that disagree with you.
    2. Re:Own a computer, own a car by plover · · Score: 3, Funny
      And people do, because they know if they don't they'll end up stranded in Bumbleshoot, Minnesota at 3 AM.

      But there are no consequences for owning a computer that's been hacked and is being used by someone else for their own nefarious purposes.

      Perhaps that's a good reason keyboards should come with built-in tazers.

      --
      John
    3. Re:Own a computer, own a car by Eberlin · · Score: 5, Insightful

      You'd get called an elitist (as I did) for suggesting the need for computer users to be competent.

      Basic computer skills are a difficult enough concept for some -- and anything past "two clicks on the blue letter E" goes over their heads. Anti-virus, firewalls, and windows update? Way too complicated. Downloading and installing another browser? That's a challenge! (I got a call once from someone who couldn't install something from CD-ROM because it wasn't set to auto-run!) Reformat a hard drive and install an alternative operating system? Definitely too much.

      There isn't any interest in knowing anything past 2 clicks on blue E. Solution? FUD 'em. (not essentially lies but fun half-truths) Tell them their machines are being constantly attacked over the net and they need to protect themselves. Teach them that their personal information can get stolen. Tell them that unless they learn the ropes, they'll have to deal with headaches and heartaches and big computer repair bills.

      Hell, tell them that without a good firewall, (Osama || Saddam || tooth fairy) will break into their computers and terrorists will win. (That method seemed to work well with the average Joe Sixpack for a different, more lethal cause).

      Either way, education is part of the solution...but you can only educate those that want to learn. The trick is to motivate people into learning and understanding computer security.

    4. Re:Own a computer, own a car by ch-chuck · · Score: 3, Interesting

      many people dont know how to change a tire or oil.

      Clearly, what is needed is a network of retail shops, call them 'Jiffy Comp' or something, for people to pop in and have their computers scanned and upgraded while they wait in the lobby watching CNN. After 20 minutes or so a jumpsuited tech would come in and say, "Mrs Pauley? We found two worms, installed service pack II and updated the virus defs. Everything is ok now but be sure to bring it back every 30 Gigabytes or 3 months. That'll be $24.95 + tax"

      --
      try { do() || do_not(); } catch (JediException err) { yoda(err); }
    5. Re:Own a computer, own a car by techno-vampire · · Score: 3, Insightful
      I dont understand why people spend thousands of dollars on a new device, then simply dont bother to learn anything about it. A computer, like a car, is a serious investment. Learn how to use it properly.

      Back when I was doing tech support, I heard almost daily from people who'd say, "I'm completely computer illiterate." Most of them would say it not in shame but in pride. They seemed to think there was something good about being incompotent and that it made them better than people who knew how to use computers. There are more of them out there than you'd like to think, and none of them want to know what they're doing. Same thing as it is with cars; knowing how to change a tire makes you lower-class in their eyes, just as knowing how to install software.

      --
      Good, inexpensive web hosting
  5. RTFM Issue by webword · · Score: 4, Insightful

    Unfortunately the folks who need the help the most are the the least likely to read. It is like a law: Those who need to RTFM are least likely to RTFM.

  6. To help explain security... by kdougherty · · Score: 3, Interesting

    Why don't you demonstrate security flaws instead of just explaining them? Show your board or whoever actuall real-time exploits and flaws so they understand what the consequences are. If not you could always use a crayon and paper... it's how I taught my mother to use email. :)

    --
    The best way to predict the future is to invent it. -Alan Kay
  7. What about Security for Dummies? by qualico · · Score: 3, Interesting

    I'm *not* being serious.

    Although, it sure would be nice on the one hand to have a well written security book for the masses, its equally important on the other to stress that using a professional is a great way to achieve the goals of protection and understanding.

    Maybe I'm just trying to create more job security for myself. :->

  8. The computer needs to solve the problem by Neil+Blender · · Score: 5, Interesting

    Most people, present and future, will probably remain ignorant forever. No book will solve the problem of internet/computer security for the masses. The computer needs to solve it. People just aren't interested.

  9. In real life by Otter · · Score: 4, Insightful

    Every society develops certain universally-known rules of thumb about safety, from "Don't swim in the muddy water near that rivermouth!" to "Stay clear of the bar where all the tweaker bikers hang out!" Eventually, we'll have universal wisdom about being careful of email attachments and avoiding phishing schemes. But it'll have to happen through word of mouth and Oprah. No one is going to read a book like this.

  10. Beyond Fear by savagedome · · Score: 3, Informative

    If you haven't read Beyond Fear by Bruce Schneier, I definitely recommend you should before buying any other security book!

  11. How Things Work by nemski · · Score: 4, Interesting

    It always amazes me that geeks think that everyone should know how a computer works. Why? Does a automechanic or plumber or electrician expect the same? I hire a guy to fix my brakes, change the oil, install a new heater and air conditioner in my house, and, frankly, I don't want to know how they do what they do.

    Before you drop into identity theft and such, how many people don't even know what they're credit score is? And you don't even need a computer to find that out.

    --
    Some people have a way with words, others not have way.
  12. Think: children's books by bennomatic · · Score: 3, Interesting
    Messages that are intended to change the way people think about things need to be delivered fast and hard. Think commercials. Or kids book. Or comic books. Grab them, get an emotional response, associate an old behavior with bad feelings, associate a new behavior with good feelings.

    I have not read the book, but based on the description, it sounds like it will be seen as most effective by people who already know what they are doing. With large numbers of anecdotes and not enough focus, it falls firmly under the heading of preaching to the choir; the only people who will probably slog through this book will be people who understand its importance before even opening it up. I've got friends who not only use easy-to-guess PIN numbers and passwords, but when participating in a conversation about the importance of security, they'll even announce their information proudly, as if it's some sort of joke. You don't change those sorts of attitudes with a textbook.

    Maybe security philosophy would be better spread through viral means such as a really funny movie (think the original South Park Xmas Jesus vs. Santa video), or a bunch of jokes that people tell. Here's one that would work on an old friend of mine: Q- What do you get when you take the area code away from your phone number? A- Your ETrade password!

    --
    The CB App. What's your 20?
  13. It's worse. by teamhasnoi · · Score: 4, Interesting
    A browser is not a 'window to the internet' but IS the Internet to most clueless users. Even though these same people would be able to tell you that, 'No, there aren't little people putting on a play for me inside my TV.', they still don't know the most basic things about using the computer.

    The tower case is the 'hard drive', the monitor is the 'computer', and even after being repeatedly told and shown what the correct terms are, it's gone in an hour.

    My dad is a perfect example. One of the first things he would do on my infrequent visits home, is take off his digital watch and have me adjust it for daylight savings time.

    "Hey, Pops - let me show you how to do this. It's easy."
    "Don't bother, I will never remember. Just set it."

    Ahhhrg. People don't remember, because they don't *want* to. I am constantly amazed at the lengths people will go to in order *not* to learn something.

  14. Not all problems are solvable by flinxmeister · · Score: 4, Insightful

    The systems of today are designed to be usable by the average Joe and Jane, but they aren't designed to be securable by that constituency.

    From a security perspective, "computers these days" are like a nuclear reactor, or a rocket, or the tax code. They're just not manageable by the average person, and the bolt on shells of security that are offered only work to a point. Without a consumer-securable security model integrated from the ground up, you're going to have melt downs, misfires, and botched returns.

    So, a book of anecdotes about "real people" and contemporary information security is almost going to be inherently uninformative. How could you possibly cover all the seams that todays severely limited security models leave open?

  15. General Security by starseeker · · Score: 4, Insightful

    I suspect we will never have universal security in the computer world, as long as it takes any effort on the part of the end user. Which leads to several conclusions:

    a) Social Engineering will ALWAYS succeed. Whatever engineers do to protect a computer, they can only protect the user from themselves up to a point. There's no cure for giving someone you think you trust your username and password, for example, and then having them rip of your confidential data. Or for that matter, keeping people from answering emails using information they shouldn't. It's a grim conclusion, but short of warning people not to be trusting nothing can be done.

    b) The machine itself CAN be made much more secure by default. This usually comes at the cost of user-friendlyness, but the username/password/account idea seems to be virtually universal now. The key to making a user friendly secure machine for the average consumer is to set up rules that allow the machine to do everything the user is likely to want to do, and ONLY that. In other words, some form of Mandatory Access Control. This is a pain in the neck for those who want to do lots of complex things on their machine, but I suspect the average needs of the modern user are becoming well defined enough to achieve something. And if applications AS PART OF THE DEVELOPMENT PROCESS create rules for what their program needs to be allowed to do (which can be externally audited to keep them honest) we might achieve a situation where it's difficult to impossible for a computer to be cracked from the outside through technological means.

    c) The bad news is, there's no market for b) and so it's unlikely it will ever happen. People have to be willing to pay the price for security, and I suspect up front cost of inconvenience (either to developers, end users, or both) will be seen as greater than the statistical potential of dangerous information theft. Whether that's true or not I don't know, certainly it varies on an individual level, but it takes herds of users to fund commercial software development and I suspect the average consumer response will be the immediate path of least inconvenience.

    d) Open Source, being outside normal economic constraints, might produce something like b) eventually. But while individual projects might code to such standards, they are probably too high a median to set for casual, unpaid development. Success would require most of the open source community to be willing to do extensive testing and planning for running their software in a MAC environment, and that's not much fun to most non-security oriented developers.

    e) So, in the end, matters will only improve when the costs of electronic theft and attack are so high they raise demand for secure systems to the economic minimum. Whether that will ever happen I don't know. My cynical guess is it won't - we'll just have to live with it. (Individual geeks of course can try to do better, but the internet has become a community. For better or worse.)

    --
    "I object to doing things that computers can do." -- Olin Shivers, lispers.org
  16. un-savvy people by qtothemax · · Score: 3, Interesting

    Kind of offtopic, but it really is true the the terms memory and hard drive don't mean anything to most people, and it took me quite a while to realize it. People are always asking me to fix thier computers when they have spyware problems, and are all worried because they have a couple games and mp3s on thier 80 gig hard drive, and think they have filled all the "memory." I have a hell of a time convincing everyone that having used 5 gigs of that 80 gig drive is no big deal and they don't have to delete everything to improve performance, though at the same time I have a hard time convincing them to turn off all the useless apps they have running in the system tray.

  17. I know nothing about computers. Take care of me. by OreoCookie · · Score: 4, Interesting

    IMHO; All operating systems should have an option that can be selected where ALL security options and ALL network configuration is set by the OS, basically saying to the OS "I know nothing about computers. Take care of me." Only if you actively choose to turn this off would you be asked to set anything yourself.

  18. sorry, not needed... by Chuck+Bucket · · Score: 3, Insightful

    Most Windows admins I know have the book "What you don't know can't hurt you", and they seem to follow that to the letter.

    CB!