Computer System Security

Posted in Buzz, Desktop Computers, Servers, Websites by admin on December 24, 2007.

Browsing some of my favorite tech blogs, I came across an article from 2005 on The Six Dumbest Ideas in Computer Security by Marcus Ranum. This is the sort of IT discussion I like to see - advanced topics tackled in a way the modestly-informed reader can understand. In short, the article outlines the absurdness of:

  1. The Default Permit - “…the computer security equivalent of empty calories…”
  2. Enumerating Badness - “…around 1992 the amount of Badness in the Internet began to vastly outweigh the amount of Goodness…”
  3. Penetrate and Patch - “…the problem with ‘Penetrate and Patch’ is not that it makes your code/implementation/system better by design, rather it merely makes it toughened by trial and error…”
  4. Hacking is Cool - “….I find it interesting to compare societal reactions to hackers as ‘whiz kids’ versus spammers as ’sleazy con artists’..”
  5. Educating Users - “…like ‘Penetrate and Patch’ if it was going to work, it would have worked by now. …”
  6. Action is Better Than Inaction - derides “…product-purchasing decisions by reading Gartner research reports and product glossies from vendors…”

 

Between the lines, Ranum is saying that computer system security should be addressed through predictive systems rather than permissive & reactive technology or training. What can average at-home users take from this? Realize your computers have vulnerabilities with people dedicated to exploit them. For tech professionals, it seems to be a much more urgent message: adapt the way you think about your world or face security as an endless, sisyphean task.

Technorati Tags: ,

del.icio.us:Computer System Security  digg:Computer System Security  spurl:Computer System Security  simpy:Computer System Security  newsvine:Computer System Security  blinklist:Computer System Security  furl:Computer System Security  reddit:Computer System Security  fark:Computer System Security  Y!:Computer System Security  magnolia:Computer System Security

3 Comments

  1. MPcomputer replied:

    Dear friend …
    thank you for nice work

    January 6th, 2008 at 1:22 am. Permalink.

  2. Jesmond Darmanin replied:

    Great find, thanks for the link, keep it up

    January 11th, 2008 at 7:59 am. Permalink.

  3. Actual Technology News Blog » Computer System Security replied:

    [...] Link [...]

    January 16th, 2008 at 12:03 pm. Permalink.

Leave a Reply

Trackback URI