Security's Everyman

Security's Everyman
Showing posts with label The Converging Network. Show all posts
Showing posts with label The Converging Network. Show all posts

Monday, October 15, 2007

Why do faster computers make us more impatient (or how technology has made us lazy)

Mitchell has answered my answer to his posting on Automatic Security. Mitchell has some valid points and I agree with him. Security software has to be user friendly. It has to be easy to use, understand and mostly not annoying or intrusive. But we still have to educate the user. If we focus on taking them completely out of the picture in making decisions then we have done nothing to benefit them or the rest of us. Our current model teaches them to click OK. So when the get a pop-up that asks them if they want to install this "add-on" they say yes. When they are asked if they want to allow malware.exe to connect to evilhacker.com they say yes. When they they are asked if they want to trust an unvalidated certificate they say yes.

We don't need to take those decisions out of their hands we need to explain to them what they mean and why answering yes may be a bad thing. One point that Mitchell made was that the default behavior for many security apps is to ask the user what they want to do. This is true, but as I said some vendors are changing that. They are looking at how the OS and various apps work and what they need to do to be useful and instead of asking "do you want to allow IE to connect to the Internet?" they are automatically allowing it to connect. They are looking at apps that are signed and allowing them to do what they are designed to do without asking the user. Another point that Mitchell made is that security software doesn't know what the user is doing or the context in which they are doing it. Again, he is exactly right. That is where we need user interaction and that is where the user needs questions and answers that are in plain English so they can make a informed choice. The software vendors have got to quit thinking like techies and start thinking like the average person when it comes to this.

Over the last decade computers have gotten faster and faster and we have gotten more and more impatient with them. They have gotten smarter and smarter and we have gotten lazier and lazier. That is the other byproduct of poorly designed technology. Just as it has taught us to click yes it has also taught us to be lazy. It has been too complex for the average person to learn so they don't even try. We have taught them that they have to sacrifice security for convenience because we have made security inconvenient without explaining it to them.

I keep going back to this over and over because there are too many out there who think that the users are never going to learn or change. As long as we make change difficult then they won't change. We need to quit expecting the worst out of them and work to make them make the right choices and learn why each choice is right or wrong.

Monday, October 08, 2007

Automatic Security?

I love and hate the Firefox addon "noscript". I use it to add an extra level of protection to my web browsing but I hate it when a site requires java or some other script to run and I haven't approved that site. It's not a big deal when I first visit the site but when I write a fairly long comment on a blog post and have it wiped out because scripting is required is really irritating. I did that this morning. Mitchell Ashley wrote a blog post on the need for security vendors to do more to take the ball out of the end users hand. I had a great (ok that's subjective) comment and it was a little lengthy but it got wiped out when I went to post it because I had scripting enabled.

So, I decided to take it to the streets. I'm going to rewrite my comment (at least what I can remember) here and see if I can get some good chatter going between Mitchell, myself and any others who may want to jump in here.

First go read Mitchell's post and then come back here. While you do that I've got a meeting to attend.

Ok, so were all back. Here are my thoughts and comments:


Mitchell, I agree with you that we need to make these issues transparent to the user to a point. Some AV/HIPS vendors are already doing this somewhat. They have taken lots of the firewall alerts and answered them "by default" so that the user isn't bothered with answering questions that they don't understand. They are making it easier for updates to be pushed/pulled to the system instead of making the users do this manually. There is still work to be done but.... Where I have a little disagreement is in completely removing the user from the fray. If we do so we may make it easier on them but we are missing out on an opportunity to educate them on the risks associated with life on the internet. We are missing the chance to teach them how to be more secure by giving them information that they can understand and then make a intelligent decision on. What I would like to see is the software vendors write alerts and pop-ups in layman's terms so that a user doesn't have to decide if it's safe to allow lsass.exe and svchost.exe to access the internet. And it gets even more confusion when the internet isn't really the internet but the internal LAN if they have one. I would like to see the vendors provide easy to understand tutorials (via the help button) that explains what the dangers of allowing or disallowing something is. We have conditioned them to click "yes" just to shut up the firewall but they have no idea what they are clicking "yes" to. I agree that User Awareness isn't the silver bullet but it has to be focused on because we can't change users behavior if we don't give them data that will educate them effectively.

Thanks for a good post that gives us something to think about. Thanks for stoking the fire of how can we make a difference and not continue to do things in the same way. What I would like to see now is how can we really make this work. What are our action points for making security transparent yet still making the user be (in the active sense) more secure?

OK, the floor is open for your comments and for you to add to the discussion on your blog. I think there is lots of good stuff here to chew on. Let's get going.

Creative Commons License
This work is licensed under a Creative Commons Attribution-NC-SA 3.0.