Humans Not Evolved for IT Security
Stony Stevenson writes to tell us that at the recent RSA Conference security expert Bruce Schneier told delegates that human beings are not evolved for security in the modern world, especially when it comes to IT. "He told delegates at the 2007 RSA Conference that there is a gap between the reality of security and the emotional feel of security due to the way our brains have evolved. This leads to people making bad choices. 'As a species we got really good at estimating risk in an East African village 100,000 years ago. But in 2007 London? Modern times are harder.'"
As a species we got really good at estimating risk in an East African village 100,000 years ago.
I wonder how many days would that guy last in an East African village 100,000 years ago.
Looking at the number of people falling for Nigerian scammers, I'd say that our ability to "estimate risk in an East African village" is not so hot either. :)
If you open yourself to the foo, You and foo become one.
Thank God I was intelligently designed for this kind of thing ;)
Knowledge is power. Knowledge shared is power lost.
Exaggerate uncommon risks -- for example, air travel is safer than cars but because car accidents are common they are seen as less risky Maybe because everyone involved in an air plane crash usually dies. Automobile deaths are much less. There's this idea of risk = probability * impact. In the case of automobiles, probability is high but the impact is low. It's the other way around in aircraft failures. Personified risk -- Osama Bin Laden is scarier than a faceless threat How in the hell does this relate to IT security? I think IT administrators are more afraid of the people they don't know hacking their systems then the people they actually employ doing the same. In the end, I'm sure more attacks come internally or from an ex-worker than someone unknown. Maybe the face you know should be more scary than the face you don't at the office? Risks that could be controlled -- The DC sniper caused a few deaths but the response was way out of proportion. Please elaborate, I know of the John Lee Malvo incident but I have no idea how this relates to IT security. Are you telling me that shutting down a system to protect a database from a possible threat or virus is overkill? I would respond with that varying on a case by case basis but at my job, offline databases are worth maintaining the integrity of the data inside them.
I know I'm really coming off as a jerk when I say this but I don't think this article helped me in anyway. All I saw was someone over simplifying a complex problem--thereby making them seem smarter to the people they were explaining it to.
Don't read this article, it has nothing to offer you. If you don't know this subject, I believe this article will only add to your confusion and lack of understanding.
My work here is dung.
"Only human."
--Agent Smith on IT security
And don't forget CYA security - security rules that aren't being followed and aren't being enforced either - but that exist solely so that when shit hits the fan, the bosses can say it was against policy. These are usually extremely draconian, impossible to implement or practicly impossible to follow while getting work done. But hey, it looks good on paper...
Live today, because you never know what tomorrow brings
If somebody breaks into my computer, will I die? No. Will I become sick of temporarily disabled? No. Will I lose money? Possible, but unlikely, and in any case the insurance company will get them back for me. Should I therefore hire a security consultant? NO!
I believe most people get this analysis right.
More importantly, we are unable to plan for long-term security. If the planets ecosystem is under attack from global warming, creating and/or spreading lots of new diseases (harming us, our food, or in some other indirect way), do we stop emitting pollutants contributing to global warming? No. Do we invest money into biological research and education so we can handle the new diseases? No. Do we invest significantly in technological countermeasures, such as painting Sahara white, building dams against floods or the rising ocean, or even storing CO2? No. Do we do anything at all? Not really, unless you count selling quotas to each other.