Slashdot Mirror


How Security Companies Peddle Snake Oil

penciling_in writes: There are no silver bullets in Internet security, warns Paul Vixie in a co-authored piece along with Cyber Security Specialist Frode Hommedal: "Just as 'data' is being sold as 'intelligence', a lot of security technologies are being sold as 'security solutions' rather than what they really are: very narrow-focused appliances that, as a best case, can be part of your broader security effort." We have to stop playing "cops and robbers" and pretending that all of us are potential targets of nation-states, or pretending that any of our security vendors are like NORAD, warn the authors.

Vixie adds, "We in the Internet security business look for current attacks and learn from those how to detect and prevent those attacks and maybe how to predict, detect, and prevent what's coming next. But rest assured that there is no end game — we put one bad guy in prison for every hundred or so new bad guys who come into the field each month. There is no device or method, however powerful, which will offer a salient defense for more than a short time. The bad guys endlessly adapt; so must we. Importantly, the bad guys understand how our systems work; so must we."

4 of 67 comments (clear)

  1. Holistic by dreamchaser · · Score: 3, Insightful

    No point product or product line of point products is a 'security solution.' They are part of the equation, but only a holistic approach that encompasses user training, proper design, constant vigilance, and yes the right point products can really be called a 'solution', and even then I tend to avoid the term. I'll speak to solutions for particular problems, for example web filtering or fire-walling, but I try to lead my clients to understand that only a complete top to bottom approach will even come close to providing them with the security they need. Even then, it's a game of leap frog. The bad actors will always be back with sneakier malware, more artful attacks, etc.

    1. Re:Holistic by khasim · · Score: 4, Insightful

      It all comes down to proper design and the ability to say "NO".

      Security cannot be retro-fitted to a badly designed system.

      The person who can demand that you support X in Y configuration NO MATTER WHAT is the person who controls your security. No matter what his/her knowledge level is.

      Next, understand that you will (eventually) be cracked. Someone somewhere will make some mistake just long enough. MONITOR for that. KNOW what the regular traffic on your network looks like. PLAN for what you are going to do WHEN that happens.

  2. All "security" tech is outright fraud by Anonymous Coward · · Score: 5, Insightful

    Security isn't a product. It's really that simple. Security comes from properly implemented instruction in code. ie that isn't riddled with bugs. Unless your selling me a service which audits the software's source code I use and/or configurations (for example Apache's configuration, SSL enabled, up-to-date, good configuration for Drupal, etc ) I'm not convinced that there is any value in your security product. Your not going to be safer unless the software your using isn't riddled with bugs and poor default settings and/or configuration.

    I have to admit that I would pay for a subscription to an auditing service for GNU/Linux. I wouldn't pay for an anti-virus solution as anti-virus software is an outright fraud. The companies can't fix bugs in the code (on proprietary platforms) and at best there is a slight chance some malicious software might get picked up (the risk and costs vs reward though isn't worth it). It won't stop new malware from exploiting old un-patched bugs and most malicious software in the will get through. 99.8% detection isn't going to do shit when 98.8% of malicious software isn't actually spreading and/or has been patched years ago.

    Yea- I don't use MS Windows or Mac OS X or any proprietary software (well, except, unfortunately a proprietary BIOS, and possibly other low-level microcode, but drivers/firmware for individual components are mostly free in my systems, ie ThinkPenguin.com).

    1. Re:All "security" tech is outright fraud by Anonymous Coward · · Score: 3, Insightful

      Having worked in a Fortune-10 (still, I think) company as a sysadmin for a chunk of their IT systems, I saw *tons* of security holes - I had a list of at least 20 things I wanted to make sure got fixed when we migrated to newer hardware(or VMs)/software, just because launching a project to fix them would have been prohibitive - why not do it all with the 'upcoming upgrade/migration' right? Nope, was taken entirely out of my hands and not only were the existing security issues that I already knew about not fixed, but dozens of "new" ones (most of which we'd already fixed in the current setup) were put *back in*. Then as various systems got security scanned, we were running around fixing *all the old bugs again*, on top of fixing a few of the easier ones I knew about with it (one's that weren't architecturally a bitch to fix once you've done it wrong in the first place).

      But hey, they've got firewalls and such right? Well... except for those pesky 300,000 internal employees that don't have to go through them...