« Squandering Venture Capital | Main | Chance of Dying in Georgia Increased »

February 06, 2007

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d8341c8bd053ef00d834e19e4053ef

Listed below are links to weblogs that reference Disregard for Security in Security Products - continued:

Comments

LaurisF

He would not be the first person to develop a tool to clone a prox technology access card. It has been known for awhile that certain students from a certain distinguished institute of higher education have done the same without the need to have possession of the card.

Good security designers take into consideration that reliance on one feature or aspect of security is like putting all your eggs in one basket. If the portal security is important enough, there can be multi-factoral identity verification concepts in play where the card is not the only item needed to gain access.

Good security programs presume that this can and does happen.

Steve Hunt

That's not the point Lauris. The point is that if the hacker community "discovers" physical security systems, they will not stop at simple RFID cards. They'll hit controllers, alarm panels, cameras, management software, etc.

LaurisF

Steve, again they have already accomplished hitting these on at least one system. Once security systems left the relative "security" of closed networks, it has been a fast paced race to build protection against the hackers that live in the public networks. Today's security will not prevent tomorrow's attack scenario. We can only protect against what we know.

OsamaS

LaurisF says: "Today's security will not prevent tomorrow's attack scenario. We can only protect against what we know."

There is some (or a lot) of truth to this statement. Yes, there is no such thing as absolute security, however I do believe that if systems are implemented from the startup with security in mind they will be able to protect against many of tomorrow's threats.
I'm talking here about basics principles like "default deny", defense in depth, least privilege, zoning etc.

I think LaurisF means "Security Technologies" when he says "Today's security".

Then there is always the issue that security technologies themselves can introduce risks, like AV software with bad signatures that delete legitimate files, security products with buffer overflow vulnerabilities etc.

To put it more optimistic, today's security principles can prevent many of tomorrows attack scenarios.

Steve Hunt

Lauris, I'm more inclined to what Osama says. You sound like you are throwing in the towel. (I'm sure you aren't, but you sound that way). Like you assume the bad guys will stay one step ahead, so what can we do? Osama on the other hand says let's use the best priciples of preparation, detection, response and remediation to battle the unknown. Bring it on, bad guys! right?

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment