Maybe Users Aren't So Funny After All

I can't stop thinking about my experience last month when I had to reload Windows XP for a friend. It makes me think we need to reconsider how we in the security world have failed the consumer. Should it really be necessary for a consumer to be a security expert to safely use a computer?

By Kenneth van Wyk
Tue, March 16, 2010

Computerworld — I can't stop thinking about my experience last month when I had to reload Windows XP for a friend. It makes me think we need to reconsider how we in the security world have failed the consumer. Should it really be necessary for a consumer to be a security expert to safely use a computer?

That seems to be our message. "You should have known not to click that link," we say. "Why would you trust that that e-mail actually came from your mother?" We get disgusted that users keep falling for old tricks. But what are we doing to actually help these people?

We should start by better understanding the misconceptions about e-mail and Web site safety that pervade the user base. For example:

* If an e-mail looks authentic, it is safe. We seem to believe that every user should be as jaded as we are. After all, spam mail, phishing attacks and all the rest have been around for years, right? We techies aren't surprised when the attacks appear to be legitimate emails. Why do users not suspect everything the way we do? We expect deception in cyberspace to be as common as it is in nature. But we shouldn't forget that a suspicious nature, so beneficial in our profession, isn't necessarily helpful to the work our users do. Instead, we are surprised -- indeed, amused -- when our well-intended users respond to an attack. And yet, really, when one of my family members last week got caught up in the wave of fake Amazon cancellation notices, what did he do that was so wrong? He responded to a message that looked legit to him, especially since he had just placed an order with Amazon.

* This e-mail came from someone I know, so I know it's safe. Again, as security pros, we are aghast that anyone could not be aware that spammers and other e-mail attackers have for years been sending out their attacks with forged "From:" addresses. We understand the mechanisms that allow the bad guys to pose as our friends. And even my friends and family members who are not very computer savvy realize that I would not contact them trying to sell black-market Viagra. But sometimes the sender and the message converge, as they did for the family member who had just placed an order on Amazon, and so they respond. "How could that e-mail not be from Aunt Lucy?" they want to know. I always tell them that e-mail messages, like postal envelopes, can be trivially made to contain any "From:" address the sender chooses to use.

Continue Reading

Originally published on www.computerworld.com. Click here to read the original story.
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.
This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make to help achieve project success.
Learn how Gartner's criteria for next generation IPS helps organizations achieve effective threat prevention despite changes in network communications, new applications, and changes in the threat landscape.
3 minute Flash video - overview of the need for and value of Configuration Control.
Cloud deployments are playing a critical role in propelling innovation for many companies. At the same time security has become the #1 one of the top concerns for IT and business leaders as they migrate into the cloud. In this webinar, learn from Accenture discusses how to recast the cloud as a "fresh chance to rethink your approach to security."
As greater numbers of datacenter servers transition from the physical to the virtual world, the components of virtualization success come to the fore. What scores of organizations have discovered is that success is derived from an optimal pairing of the right software platform with the right hardware platform.
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn about VMware customer, Navicure, and their experiences testing and evaluating the recovery manager, their progress in implementing it in their environment and their advice other customers considering using vCenter.
Many enterprises have discovered that the use of virtualization to support desktop workloads creates a range of significant benefits. These benefits include price efficiencies, improved IT management and greater agility and choice for end users.

This VMware sponsored webcast with IDC will provide both quantitative measurement of the business value -- defined as the expected ROI -- and qualitative analysis associated with the use of VMware View™. IDC will also provide an analysis of the View Composer and ThinApp™ features of VMware View, including the business value of these solutions and an overview of how they work.

Attend this webcast to learn about:
- Challenges and barriers that might impede the adoption of desktop virtualization
- Navigating roadblocks to facilitate a strategic implementation
- Optimizing qualitative and quantitative benefits to IT and your business
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all Newsletters | Privacy Policy
Resource Center