Sounds like it was getting a little thick out in California this week at the RSA ‘07 conference as one of the security industry’s most outspoken experts, Bruce Schneier took security and its related issues to a new, higher plane. He said network security decisions and perceptions are often driven by irrational and subconscious motives in human beings. My colleague Ellen Messmer writes Schneier, the CTO at BT Counterpane, said security managers need to be aware that they themselves, their business managers and their corporate user groups are likely to make critical security decisions based on barely acknowledged impressions of fear and irrational response, rather than a careful study of facts. Schneier based his observations on his own study of tracts written in the fields of behavioral science, human psychology and university research about how people make choices. He said there’s reason to believe that decision-making in security is much less rational than one would prefer. I don’t know, you’d think with some of these systems costing thousands of dollars or more there’d be SOME rationality. Maybe that’s just me. Schneier, you may recall is the developer of the Blowfish and Twofish encryption algorithms and as the bestselling author of Applied Cryptography, which has been called the hackers bible.
Security philosophy and the theory of om; or why your network was hacked
Opinion
Feb 7, 20072 mins




