The Wrong Attitude Towards Security
My biggest issue with the security field and the people in it is the attitude towards the user base at large. When a user is infected it’s almost always considered to be their fault – they went to a malicious page, they were tricked into installing a malicious program, they were tricked by a man on the phone, etc, must be their fault.
To look at millions of infected systems and say “the system is fine, the users are the issue” is backwards. Systems are meant to serve users, not the other way around.
This attitude needs to change if security is going to progress. Security models need to be built around the idea that developers of applications won’t care about security, or know enough to be secure, and the users of those applications either don’t know or don’t care to be secure either.
A security model that assumes users will answer a prompt correctly without providing them with blatant and clear information, will fail. A security model that allows developers to opt into security features will fail.
So until someone takes these issues into account, issues that have historically never wavered, there will be millions of infections.
blog comments powered by Disqus