earlier today i sent out a tweet mentioning a security awareness initiative by the folks at eset and that started off a brief discussion with michael santarchangelo about security awareness and adoption thereof. it could have been a longer discussion, but i quickly realized i had more to say about the subject than could reasonably fit in twitter.
the reason we talk about security awareness is that most people seemingly lack such awareness. but what does that mean? well one of the things it means is that people don't think about the consequences of their actions, they don't think about the possible outcomes. this isn't just some people, either. as michael pointed out, it's all people, even you and i to some degree fail to account for all the possible outcomes. it's also not just about security, but rather about virtually any kind of awareness. some of us are more aware of certain things than others are, and aware of some things more than other things, and of course the amounts are different for each person.
we could, of course, think about such things more so why don't we? in a word: laziness. now i don't mean that in a judgmental way. although laziness certainly isn't well regarded in this day and age, it's not just some character flaw in humans. the argument could be made that it served a purpose, once upon a time. physical laziness, at least, serves to conserve energy, which would have been an advantageous evolutionary trait back before we started to gain mastery over our environment, when food was harder to come by. wasting energy foolishly could have hastened starvation, so the fact that we developed a tendency to conserve our strength for when we really needed it is probably a good thing, even though the adaptation doesn't serve us nearly as well now that food is (at least in developed nations) relatively plentiful.
i'm not about to suggest that mental laziness shares the same lineage as physical laziness, however. it would be quite the stretch to suggest that thinking too hard could lead to starvation. mental laziness is something i've been thinking about for a while, why it's there and how to overcome it*. at some point it occurred to me that every moment a person spends thinking about outcomes is a moment that one isn't being in the moment. being in the moment is one of the hallmarks of happiness. being focused on the present instead of the past or the future is something one only does when one is content. one could, then, argue that people don't think about outcomes unless they really have to because it means giving up (if only temporarily) a state of mind in which they experience happiness.
that seems a little wishy washy to me, though, and while i was chatting with michael i had an idea about a possible root of mental laziness that is more like the one for physical laziness i described above. having a tendency to focus on the here and now could have been an advantageous evolutionary trait. being lost in thought when you're out in the wild and you're not the top of the food chain is a good way to become lunch for something else. those that spent too long thinking about abstract concepts got eaten while those who maintained a presence of mind lived on. the fact that contentment and happiness are linked to that mental state could be a neurological reward that evolved to reinforce what was once a beneficial behaviour (it feels good so do it more), much like our tendency to prefer sugary/fatty foods would have aided us in prioritizing energy rich foods when food was less plentiful (it tastes good so eat it more).
of course, the world of today is much different than the world in which such evolutionary traits would have developed, so they don't serve us nearly as well as they once might have. those neurological rewards still reinforce the behaviours in spite of the fact that they're they're no longer advantageous. some of us have, whether through genetics or conscious effort, become better adapted to various realities of the modern world. those of use who have should count ourselves as lucky rather than looking down our noses at those who haven't adapted as quickly. fighting against millions of years of evolution can't be easy and few of us are really that much further along than anyone else.
i offer these thoughts to serve as a form of perspective. it would be nice if we could just read some books or articles, or attend some classes and then magically overcome whatever it is that is holding back our security awareness. but if i'm right then at least part of what holds us back dates back to the dawn of man, if not earlier. such intrinsic aspects of humanity are not so easily changed, and yet we continue to evolve and adapt.
(*to a certain extent i started trying to overcome others' mental laziness with respect to security with http://www.secmeme.com long before i ever started to think in terms of mental laziness. if i were to describe it uncharitably, i'd say i was trying to trick people into thinking more about security.)
devising a framework for thinking about malware and related issues such as viruses, spyware, worms, rootkits, drm, trojans, botnets, keyloggers, droppers, downloaders, rats, adware, spam, stealth, fud, snake oil, and hype...
Showing posts with label user education. Show all posts
Showing posts with label user education. Show all posts
Monday, June 27, 2011
Thursday, July 01, 2010
AMTSO revisited
in keeping with my habit of subtracting 1 from infinity, i've found that kevin townsend's recent post about AMTSO is just calling out for correction. the challenge, it seems, is where to start.
there are two primary questions he tries to answer, the first of which being whether or not AMTSO is serious about improving anti-malware testing. he concludes that the answer is no and holds up VB100 as an example to support this conclusion because he thinks if they were serious about improving anti-malware testing they'd ban the VB100 test on the basis that it misleads the public. of course, in reality AMTSO hasn't done that because they can't. they don't have the power to do so. AMTSO is trying to create improved standards but they don't have the authority to enforce those standards. all they can do is use indirect means to exert pressure on testing organizations to improve their methods. anyone reading the AMTSO FAQs, especially the one about their charter, can plainly see that enforcement is neither explicitly mentioned nor implicitly referred to.
additionally, VB100 isn't actually a test in it's own right. it's a certification/award based on a subset of the results of a larger comparative review. kevin should have known this had he bothered to read the first sentence of the VB100 test procedures. furthermore, the VB100 award itself is not misleading. this is one instance when we really ought to be shooting the messenger because the misleading is being done by vendor marketing departments which happen to use the VB100 award in an incredibly superficial and manipulative way (and frankly there's little that testers could do to stop that). there actually isn't all that much wrong with the VB100 award except that, due to it's being based on the WildList, it has lost most of it's relevance. that said, certifications in general have limited relevance as all they really do is help to establish a lower bound on quality. a lot of people don't understand this or even what VB100 really is, but that lack of understanding is hardly the fault of virus bulletin, especially when most people don't even go to the virus bulletin site to learn what the results mean.
before i move on to the second of kevin's main questions, i'd like to take an aside and look at something he wrote about the WildList itself:
the second of kevin's main questions had to do with whose interests AMTSO was really serving. he concludes that they serve the vendors interests rather than the end user's based on his assumptions about the reason behind their adherence to the rule about not creating new malware, but also based on his decision to buy into the spin being put forth by NSS Labs CEO rick moy.
for starters i can't believe that after all these years people are still getting bent out of shape or trying to read ulterior motives into the 'no malware creation' rule. it's one of the oldest and most fundamental ethical principles in the anti-malware community. if people found out that the CDC was creating new diseases they'd be up in arms - worse still if one of those new diseases got out (something which has happened in the malware world) - but in the case of the anti-malware community outsiders assume it's because everyone in the anti-malware community has vendor ties and the vendors don't want to look bad in tests. we're not talking about the 'we mostly frown on malware except when it's useful to us' community, it's the ANTI-malware community. you can't really call yourself anti-X if you go around making X's. that would just make you a hypocrite.
furthermore, and speaking directly to the following rather uninformed rhetorical question kevin puts forward about the 'no malware creation' rule:
as for believing the NSS spin and using the 2 test reviews available (yes, what an incredibly small sample size) on the AMTSO site to try and support that view i offer the following support to the counter-argument: retrospective tests have made far more vendors look far worse than NSS's test did and no one is challenging the results. no one is using the AMTSO review process to dismiss those tests, as kevin phrased it. how can the conspiracy theory about protectionism in AMTSO be true if nobody is trying to discredit tests that are even more damning and damaging than NSS'? if you think it's because the tests are too obscure, think again - they're produced by some of the top names in independent anti-malware testing (even NSS' own vikram phatak recognized one of the organizations as being independent in that video i've referenced twice before), who also happen to be a part of AMTSO.
kevin believed the spin, i suspect, because he was predisposed to. previous posts on his blog show an existing bias against AMTSO, apparently due in part to the involvement of vendors. there is a very sad tendency in the general security community to not be able to see past a person's vendor affiliations. apparently people think that if you work for a vendor you're nothing more than a mouthpiece for your employer and that the entire company is one big unified collective entity. no attempts are made to distinguish between divisions within the company and recognize the huge difference between the technical people and the business people in those companies (you never know what you're going to get when the two overlap, though - just compare frisk with eugene kaspersky). it's not the business people, the marketroids (so called in order to distinguish them from actual human beings), or the HR departments participating in AMTSO, it's the researchers.
one final idea that kevin put forward in his post is the importance of the user - going so far as to suggest that users should be part of AMTSO, that users determine whether tests are any good, etc. i don't know what on earth he was thinking, but the layman hasn't the tools to divine good science from bad. most users (and i say this as a user myself) haven't got the first clue about what makes a good test or a biased test. in fact most users don't read or interact with tests at all. the only thing they know about tests is what they read in vendor marketing material (usually on the cover of the box), which, as previously mentioned, neither testers nor AMTSO have any control over. i really don't see what users could bring to AMTSO, but i do see something that AMTSO could bring to users - that being tools for to help them understand the tests, to put them in the proper perspective, and yes to also be able to pick out the good ones from the bad.
to be perfectly honest, i understand some of the indignation kevin is directing towards testers and by extension AMTSO, but i think it's misdirected. for most people, marketing is the first and sometimes only voice they hear with respect to security. it's marketing's job to distort and/or omit facts in order to make the company and it's product/service look good. of course marketing does this at the behest of management, of CEOs and shareholders, and people whose concerns are business and profit rather than the good of the user. none of that has anything to do with testing or AMTSO, however.
there are two primary questions he tries to answer, the first of which being whether or not AMTSO is serious about improving anti-malware testing. he concludes that the answer is no and holds up VB100 as an example to support this conclusion because he thinks if they were serious about improving anti-malware testing they'd ban the VB100 test on the basis that it misleads the public. of course, in reality AMTSO hasn't done that because they can't. they don't have the power to do so. AMTSO is trying to create improved standards but they don't have the authority to enforce those standards. all they can do is use indirect means to exert pressure on testing organizations to improve their methods. anyone reading the AMTSO FAQs, especially the one about their charter, can plainly see that enforcement is neither explicitly mentioned nor implicitly referred to.
additionally, VB100 isn't actually a test in it's own right. it's a certification/award based on a subset of the results of a larger comparative review. kevin should have known this had he bothered to read the first sentence of the VB100 test procedures. furthermore, the VB100 award itself is not misleading. this is one instance when we really ought to be shooting the messenger because the misleading is being done by vendor marketing departments which happen to use the VB100 award in an incredibly superficial and manipulative way (and frankly there's little that testers could do to stop that). there actually isn't all that much wrong with the VB100 award except that, due to it's being based on the WildList, it has lost most of it's relevance. that said, certifications in general have limited relevance as all they really do is help to establish a lower bound on quality. a lot of people don't understand this or even what VB100 really is, but that lack of understanding is hardly the fault of virus bulletin, especially when most people don't even go to the virus bulletin site to learn what the results mean.
before i move on to the second of kevin's main questions, i'd like to take an aside and look at something he wrote about the WildList itself:
this latency means that, almost by definition, the Wild List includes little, if any, of the biggest threat to end-users: zero-day malwarewhat kevin and many before him have failed to realize is that the reason zero-day malware is as big a threat as it is today is because it's competition has been largely eliminated thanks to a focus on the WildList. without that we'd still be getting compromised by the exact same malware year after year because the stuff that was demonstrably in the wild wouldn't be getting higher priority treatment.
the second of kevin's main questions had to do with whose interests AMTSO was really serving. he concludes that they serve the vendors interests rather than the end user's based on his assumptions about the reason behind their adherence to the rule about not creating new malware, but also based on his decision to buy into the spin being put forth by NSS Labs CEO rick moy.
for starters i can't believe that after all these years people are still getting bent out of shape or trying to read ulterior motives into the 'no malware creation' rule. it's one of the oldest and most fundamental ethical principles in the anti-malware community. if people found out that the CDC was creating new diseases they'd be up in arms - worse still if one of those new diseases got out (something which has happened in the malware world) - but in the case of the anti-malware community outsiders assume it's because everyone in the anti-malware community has vendor ties and the vendors don't want to look bad in tests. we're not talking about the 'we mostly frown on malware except when it's useful to us' community, it's the ANTI-malware community. you can't really call yourself anti-X if you go around making X's. that would just make you a hypocrite.
furthermore, and speaking directly to the following rather uninformed rhetorical question kevin puts forward about the 'no malware creation' rule:
Why not? How can you test the true heuristic behavioral capabilities of an AV product without testing it against a brand new sample that you absolutely know it has never experienced before?it is already possible to test anti-malware products against malware they've never seen before without creating new malware. it's been possible for a long, long time. it's called retrospective testing, and anyone with familiarity with tests (not even testing issues, just the tests themselves) knows that retrospective tests make vendors look terrible. detection rates around 40% used to be the norm but in more recent times they've edged up closer to 50%. there are still some below the 40% mark, though, and even some below the 20% mark.
as for believing the NSS spin and using the 2 test reviews available (yes, what an incredibly small sample size) on the AMTSO site to try and support that view i offer the following support to the counter-argument: retrospective tests have made far more vendors look far worse than NSS's test did and no one is challenging the results. no one is using the AMTSO review process to dismiss those tests, as kevin phrased it. how can the conspiracy theory about protectionism in AMTSO be true if nobody is trying to discredit tests that are even more damning and damaging than NSS'? if you think it's because the tests are too obscure, think again - they're produced by some of the top names in independent anti-malware testing (even NSS' own vikram phatak recognized one of the organizations as being independent in that video i've referenced twice before), who also happen to be a part of AMTSO.
kevin believed the spin, i suspect, because he was predisposed to. previous posts on his blog show an existing bias against AMTSO, apparently due in part to the involvement of vendors. there is a very sad tendency in the general security community to not be able to see past a person's vendor affiliations. apparently people think that if you work for a vendor you're nothing more than a mouthpiece for your employer and that the entire company is one big unified collective entity. no attempts are made to distinguish between divisions within the company and recognize the huge difference between the technical people and the business people in those companies (you never know what you're going to get when the two overlap, though - just compare frisk with eugene kaspersky). it's not the business people, the marketroids (so called in order to distinguish them from actual human beings), or the HR departments participating in AMTSO, it's the researchers.
one final idea that kevin put forward in his post is the importance of the user - going so far as to suggest that users should be part of AMTSO, that users determine whether tests are any good, etc. i don't know what on earth he was thinking, but the layman hasn't the tools to divine good science from bad. most users (and i say this as a user myself) haven't got the first clue about what makes a good test or a biased test. in fact most users don't read or interact with tests at all. the only thing they know about tests is what they read in vendor marketing material (usually on the cover of the box), which, as previously mentioned, neither testers nor AMTSO have any control over. i really don't see what users could bring to AMTSO, but i do see something that AMTSO could bring to users - that being tools for to help them understand the tests, to put them in the proper perspective, and yes to also be able to pick out the good ones from the bad.
to be perfectly honest, i understand some of the indignation kevin is directing towards testers and by extension AMTSO, but i think it's misdirected. for most people, marketing is the first and sometimes only voice they hear with respect to security. it's marketing's job to distort and/or omit facts in order to make the company and it's product/service look good. of course marketing does this at the behest of management, of CEOs and shareholders, and people whose concerns are business and profit rather than the good of the user. none of that has anything to do with testing or AMTSO, however.
Monday, June 14, 2010
the security user conversion problem
i'm going to start out by saying that i believe in the effectiveness of user education in making users better able to protect themselves. i have to - i'm a product of self-directed user education - not believing in user education would be the same as not believing in myself.
and what's not to believe in? over 20 years of computing with only a single partial compromise (malware got in but was effectively neutered due to my precautions and environment). that's a better track record than a lot of people who work in the security industry, and i don't work in that industry. that doesn't make me a security expert, mind you, (in fact, i refuse to accept that title) but simply what i like to call a security user (a user of security, it's concepts, it's techniques, etc).
i don't know what specific security goals other proponents of user education have in mind. i've never asked any of them and perhaps i should have. mine is pretty simple, though. it seems to me that other people would be a lot better off, or at least a lot more secure ("better off" might be too open ended) if they were more like me. i know that seems rather egocentric but i was a teenager when i arrived at that conclusion so a certain amount of egocentricity is not unsurprising, and to be perfectly honest there hasn't been anything in the years since to change my mind.
so the question i have been grappling with since i was a teenager is 'how do i make others more like me?', which is to say how do i turn ordinary users into security users? it's a challenging problem and one that i've been working on for years. everything from providing strategies for people to follow (in the form of the anti-virus cookbook, originally written in the pre-windows days), to making information more available and easily found (through the anti-virus reference library), to simply trying to guide the way people think (which i use this blog for), to even trying a bit of memetic engineering (over at security memetics - and i use the term memetic engineering loosely). unfortunately those efforts haven't had the effect i'd been hoping for so i can definitely see both sides of the user education efficacy debate - on the one hand i know it works (it worked on me), but on the other hand it doesn't seem to be working.
obviously something is missing but what? how is it that i became a security user and the people around me generally don't even ask for advice? therein, i think, lies the clue. i've already framed security as a broad class of strategies for satisfying one's need for safety. if the people around me felt their need for online safety wasn't being met then asking their friendly neighborhood security nut would be one of the easiest approaches to changing that. in the absence of that happening i'm left to conclude they don't actually feel their needs for safety aren't being met. the lack of adoption of security best practices could easily be due to this fact alone - people feel safe enough already and don't feel the need to take any added measures. their perceived needs are already being met.
does that mean in contrast that i became a security user because i didn't feel safe? that's certainly an easy conclusion to jump to. but what about now? i'm still learning, still evolving as a security user - am i doing that because i still feel unsafe? that doesn't ring true to me. i feel pretty safe and i think i've got most of my bases covered. if i look back at the beginning, at my beginning on this path, i have to go back pretty far. i've recounted before the story of how i got interested in malware when i was 14, but what i haven't discussed openly before is that my association with security (even computer security) predates the events in that story. i started teaching myself programming at the age of 10 and my first user input prompt was a password prompt. nevermind the fact that it was a vic20 with a tape drive and at 10 i didn't have anything that needed to be protected, i obviously already had a pre-existing appreciation for security (and a rudimentary understanding of how to apply those concepts to computers). i can think of any number of early childhood experiences that could be responsible - all of them, admittedly, incidents after a fashion, but virtually everyone has encountered those sorts of incidents in their lives at one time or another without instilling in them an appreciation for security. more pointedly, people encounter computer security incidents now and still don't develop an appreciation for security.
that, i think, is an important point, because the basic premise of user awareness is to make the user aware of how unsafe they are - nothing should drive that point home better than an actual incident. by showing people that they are not actually safe you are creating (or revealing) a state where their needs are not being met and the universal reaction to this is fear (and possibly anger if you're the one threatening their needs). inevitably it's the application of fear in order to drive change, and personally i find the concept of playing on people's fears distasteful. i also suspect that it is an exercise in futility in the presence security vendor marketing types who have a long and successful history of dispelling fears as a means of selling product.
beyond that, i don't really think of myself as being afraid, so using fear on others doesn't really mesh with the idea of making people more like me. before i bore the remaining 3 readers to death i'll try and get to the point. i was taught at a very early age the value of arguing as a learning tool. it taught me to the importance of looking up facts and figures in order to support or disprove my own hypotheses, but more importantly it taught me to question and not believe everything i heard or read. it taught me to be skeptical. it taught me doubt. one of the things i've observed over the years is that others don't regard arguments in quite as positive a light as i do - and they also don't seem as quick to form doubts, to question or challenge those who supposedly know more. that's a shame because skepticism is the foundation of critical thinking, it is the the cornerstone of the advancement of human knowledge. if we believed everything we were told we'd still be living in caves and using stone tools.
and that, i think, is the missing ingredient in making people more like me - not fear that their needs aren't being met, but skepticism about whether X, Y, or Z can really make them as safe as the box says. skepticism about whether what their local smart guy says is right. even skepticism about whether security experts have it right. security marketing may be good at dispelling fears, but when it comes to doubts (especially reasonable ones) it's an entirely different ball game - and once people start doubting the easy answers those answers won't be able distract people from the search for what will really satisfy their needs for safety. everytime you use fear to drive change you're just feeding the marketing machine more fuel to turn that change you hoped for into mindless consumerism. we need to sow the seeds of reasonable doubt, to foster skepticism and train people to question and challenge more - not just so that they'll become more secure but so that they'll become fundamentally better at critical thinking.
and what's not to believe in? over 20 years of computing with only a single partial compromise (malware got in but was effectively neutered due to my precautions and environment). that's a better track record than a lot of people who work in the security industry, and i don't work in that industry. that doesn't make me a security expert, mind you, (in fact, i refuse to accept that title) but simply what i like to call a security user (a user of security, it's concepts, it's techniques, etc).
i don't know what specific security goals other proponents of user education have in mind. i've never asked any of them and perhaps i should have. mine is pretty simple, though. it seems to me that other people would be a lot better off, or at least a lot more secure ("better off" might be too open ended) if they were more like me. i know that seems rather egocentric but i was a teenager when i arrived at that conclusion so a certain amount of egocentricity is not unsurprising, and to be perfectly honest there hasn't been anything in the years since to change my mind.
so the question i have been grappling with since i was a teenager is 'how do i make others more like me?', which is to say how do i turn ordinary users into security users? it's a challenging problem and one that i've been working on for years. everything from providing strategies for people to follow (in the form of the anti-virus cookbook, originally written in the pre-windows days), to making information more available and easily found (through the anti-virus reference library), to simply trying to guide the way people think (which i use this blog for), to even trying a bit of memetic engineering (over at security memetics - and i use the term memetic engineering loosely). unfortunately those efforts haven't had the effect i'd been hoping for so i can definitely see both sides of the user education efficacy debate - on the one hand i know it works (it worked on me), but on the other hand it doesn't seem to be working.
obviously something is missing but what? how is it that i became a security user and the people around me generally don't even ask for advice? therein, i think, lies the clue. i've already framed security as a broad class of strategies for satisfying one's need for safety. if the people around me felt their need for online safety wasn't being met then asking their friendly neighborhood security nut would be one of the easiest approaches to changing that. in the absence of that happening i'm left to conclude they don't actually feel their needs for safety aren't being met. the lack of adoption of security best practices could easily be due to this fact alone - people feel safe enough already and don't feel the need to take any added measures. their perceived needs are already being met.
does that mean in contrast that i became a security user because i didn't feel safe? that's certainly an easy conclusion to jump to. but what about now? i'm still learning, still evolving as a security user - am i doing that because i still feel unsafe? that doesn't ring true to me. i feel pretty safe and i think i've got most of my bases covered. if i look back at the beginning, at my beginning on this path, i have to go back pretty far. i've recounted before the story of how i got interested in malware when i was 14, but what i haven't discussed openly before is that my association with security (even computer security) predates the events in that story. i started teaching myself programming at the age of 10 and my first user input prompt was a password prompt. nevermind the fact that it was a vic20 with a tape drive and at 10 i didn't have anything that needed to be protected, i obviously already had a pre-existing appreciation for security (and a rudimentary understanding of how to apply those concepts to computers). i can think of any number of early childhood experiences that could be responsible - all of them, admittedly, incidents after a fashion, but virtually everyone has encountered those sorts of incidents in their lives at one time or another without instilling in them an appreciation for security. more pointedly, people encounter computer security incidents now and still don't develop an appreciation for security.
that, i think, is an important point, because the basic premise of user awareness is to make the user aware of how unsafe they are - nothing should drive that point home better than an actual incident. by showing people that they are not actually safe you are creating (or revealing) a state where their needs are not being met and the universal reaction to this is fear (and possibly anger if you're the one threatening their needs). inevitably it's the application of fear in order to drive change, and personally i find the concept of playing on people's fears distasteful. i also suspect that it is an exercise in futility in the presence security vendor marketing types who have a long and successful history of dispelling fears as a means of selling product.
beyond that, i don't really think of myself as being afraid, so using fear on others doesn't really mesh with the idea of making people more like me. before i bore the remaining 3 readers to death i'll try and get to the point. i was taught at a very early age the value of arguing as a learning tool. it taught me to the importance of looking up facts and figures in order to support or disprove my own hypotheses, but more importantly it taught me to question and not believe everything i heard or read. it taught me to be skeptical. it taught me doubt. one of the things i've observed over the years is that others don't regard arguments in quite as positive a light as i do - and they also don't seem as quick to form doubts, to question or challenge those who supposedly know more. that's a shame because skepticism is the foundation of critical thinking, it is the the cornerstone of the advancement of human knowledge. if we believed everything we were told we'd still be living in caves and using stone tools.
and that, i think, is the missing ingredient in making people more like me - not fear that their needs aren't being met, but skepticism about whether X, Y, or Z can really make them as safe as the box says. skepticism about whether what their local smart guy says is right. even skepticism about whether security experts have it right. security marketing may be good at dispelling fears, but when it comes to doubts (especially reasonable ones) it's an entirely different ball game - and once people start doubting the easy answers those answers won't be able distract people from the search for what will really satisfy their needs for safety. everytime you use fear to drive change you're just feeding the marketing machine more fuel to turn that change you hoped for into mindless consumerism. we need to sow the seeds of reasonable doubt, to foster skepticism and train people to question and challenge more - not just so that they'll become more secure but so that they'll become fundamentally better at critical thinking.
Tags:
security,
security user,
user education
Tuesday, May 20, 2008
the user is responsible but ill-equipped
no doubt by now many of you have read about microsoft saying that the reason there was more malware on vista than on windows 2000 was because of the user... there's been a bit of a knee-jerk reaction against this but to a certain extent microsoft is actually right...
robert sandilands demonstrates this reaction against microsoft's argument quite well in his post "Is Vista more or less secure than Windows 2000?"... in fact, when he started talking about how the user shouldn't need to be security experts and just want to get their job done i felt like i was greeting an old acquaintance (i'm referring of course to the argument - robert and i are not actually acquainted yet)...
it's true that computer users shouldn't need to be security experts and it's certainly not realistic to expect they can be, that much i'll agree with, but there's another truth that some don't seem like they want to face: being security vegetables isn't really going to work out for the user either...
i shouldn't need to be an automotive expert in order to drive from point A to point B... i just want to get to my destination and don't want to be bothered with all the technical details... that should be possible, shouldn't it? sure is, but if i want to get there safely i have to follow certain safety protocols colloquially known as the rules of the road... the average person (with some notable darwinian exceptions) understands the need for following safety rules while cruising down the highway, but for the most part they aren't even aware of the existence of the security rules for using computers (were you expecting an information superhighway reference here?)...
mostly they just know they need an anti-virus product... maybe some of them have heard of a firewall, but for most people that's the extent of their awareness of secure computing behaviour and unfortunately that is not enough to keep them safe/secure...
people often liken using a computer to using a mundane household appliance like a toaster, but such people should get over themselves because even with a toaster people need to know not to stick a fork in it... there are safety rules for virtually every tool in existence - some are simply a matter of common sense (though really they're often things we pick up from safety awareness initiatives when we're young), some should be a matter of common sense (like not operating a propane barbecue indoors), and some require the consumer be informed of how to use the tool safely...
using a computer is one of those things where the consumer needs to be informed because safe/secure computer use behaviours haven't penetrated our culture yet, and because the cause is often too far removed from the effect for users to make the necessary connection... and like it or not, the cause often involves the user - when the user gets malware on their system it is usually at least partially as a result of something s/he did or did not do...
that makes the user responsible for what happens to their machine... note that this isn't the same as blaming the user, being responsible and being at fault are two different things... you can't blame someone if there wasn't a reasonable expectation for them to know better, and currently such an expectation wouldn't be reasonable... in the grand scheme of things, however, it should be reasonable; we should be able to expect that of computer users - if boy scouts can "always be prepared" then why are we still feeding computer users pablum instead of teaching them to take responsibility for their actions/inactions and the consequences thereof...
robert sandilands demonstrates this reaction against microsoft's argument quite well in his post "Is Vista more or less secure than Windows 2000?"... in fact, when he started talking about how the user shouldn't need to be security experts and just want to get their job done i felt like i was greeting an old acquaintance (i'm referring of course to the argument - robert and i are not actually acquainted yet)...
it's true that computer users shouldn't need to be security experts and it's certainly not realistic to expect they can be, that much i'll agree with, but there's another truth that some don't seem like they want to face: being security vegetables isn't really going to work out for the user either...
i shouldn't need to be an automotive expert in order to drive from point A to point B... i just want to get to my destination and don't want to be bothered with all the technical details... that should be possible, shouldn't it? sure is, but if i want to get there safely i have to follow certain safety protocols colloquially known as the rules of the road... the average person (with some notable darwinian exceptions) understands the need for following safety rules while cruising down the highway, but for the most part they aren't even aware of the existence of the security rules for using computers (were you expecting an information superhighway reference here?)...
mostly they just know they need an anti-virus product... maybe some of them have heard of a firewall, but for most people that's the extent of their awareness of secure computing behaviour and unfortunately that is not enough to keep them safe/secure...
people often liken using a computer to using a mundane household appliance like a toaster, but such people should get over themselves because even with a toaster people need to know not to stick a fork in it... there are safety rules for virtually every tool in existence - some are simply a matter of common sense (though really they're often things we pick up from safety awareness initiatives when we're young), some should be a matter of common sense (like not operating a propane barbecue indoors), and some require the consumer be informed of how to use the tool safely...
using a computer is one of those things where the consumer needs to be informed because safe/secure computer use behaviours haven't penetrated our culture yet, and because the cause is often too far removed from the effect for users to make the necessary connection... and like it or not, the cause often involves the user - when the user gets malware on their system it is usually at least partially as a result of something s/he did or did not do...
that makes the user responsible for what happens to their machine... note that this isn't the same as blaming the user, being responsible and being at fault are two different things... you can't blame someone if there wasn't a reasonable expectation for them to know better, and currently such an expectation wouldn't be reasonable... in the grand scheme of things, however, it should be reasonable; we should be able to expect that of computer users - if boy scouts can "always be prepared" then why are we still feeding computer users pablum instead of teaching them to take responsibility for their actions/inactions and the consequences thereof...
Wednesday, March 05, 2008
why anti-virus vendors are having such a hard time
ok, first of all, the fact that there are a bunch of links back to this blog has absolutely nothing to do with why i'm responding to a post about why anti-virus products are having a hard time... that said, wow, i'm glad somebody liked those posts...
the links just spelled out some backstory, as it were... the main thrust was to highlight two reasons why av products are (or at least seem to be) having a hard time...
the two reasons given are technically about why scanners specifically are becoming less effective against malware... i agree that the reasons given are contributing to problems for scanners - packers make it easy to turn a known piece of malware into an unknown piece of malware, and pre-release detection testing helps avoid releasing malware that heuristics would detect...
but both of these things (besides being outside the scope of what known-malware scanning is supposed to handle since they specifically deal with new/unknown malware) are largely out of the av vendor's control... there is something that av vendors do have control over that is contributing even more to av products seeming to have a hard time - that being a failure to adequately manage their users... they've failed to manage user understanding of threats, they've failed to manage user awareness of the tools available for mitigating the risk posed by those threats (leading to the notion that av products are just scanners - a notion that is so pervasive that most security bloggers, including the one whose article i'm responding to, give opinions and pose logical arguments based on the assumption that it's true), and ultimately (and as a result of their other failures) they've failed to manage user expectations about what those tools can do... the real reason scanners specifically are having such a hard time is that they don't get the backup they require... they were never meant to handle all malware problems (and certainly never capable of it), only known malware problems...
one of the most novel examples of this failure is the rising anti-botnet market as discussed in this eweek article on the said market... one of the first anti-botnet applications i heard about in the mainstream was the one being provided by symantec... they released it as a separate stand alone tool and though i hoped they'd see the light and integrate it into their main anti-malware offering it seems that they've decided instead to treat it as and exciting new potential revenue stream and started charging money for it (not that i think there's anything wrong with charging money for a product, but if it's product-ready then why is it separate from the rest of their anti-malware offerings? or alternatively, if they're going to offer individual tools as well as suites, why aren't there more stand-alone tools?)... this fracturing of the anti-malware market comes at the expense of being able to communicate a clear and comprehensive message to the user/customer about anti-malware security.... without anything else to tell them how anti-malware security works (and for the most part there isn't anything else that regular people would be exposed to), the way the technologies themselves are presented implicitly communicates this to the user and fracturing your own set of offerings to make some extra green is a failure to properly manage this implicit message...
the links just spelled out some backstory, as it were... the main thrust was to highlight two reasons why av products are (or at least seem to be) having a hard time...
the two reasons given are technically about why scanners specifically are becoming less effective against malware... i agree that the reasons given are contributing to problems for scanners - packers make it easy to turn a known piece of malware into an unknown piece of malware, and pre-release detection testing helps avoid releasing malware that heuristics would detect...
but both of these things (besides being outside the scope of what known-malware scanning is supposed to handle since they specifically deal with new/unknown malware) are largely out of the av vendor's control... there is something that av vendors do have control over that is contributing even more to av products seeming to have a hard time - that being a failure to adequately manage their users... they've failed to manage user understanding of threats, they've failed to manage user awareness of the tools available for mitigating the risk posed by those threats (leading to the notion that av products are just scanners - a notion that is so pervasive that most security bloggers, including the one whose article i'm responding to, give opinions and pose logical arguments based on the assumption that it's true), and ultimately (and as a result of their other failures) they've failed to manage user expectations about what those tools can do... the real reason scanners specifically are having such a hard time is that they don't get the backup they require... they were never meant to handle all malware problems (and certainly never capable of it), only known malware problems...
one of the most novel examples of this failure is the rising anti-botnet market as discussed in this eweek article on the said market... one of the first anti-botnet applications i heard about in the mainstream was the one being provided by symantec... they released it as a separate stand alone tool and though i hoped they'd see the light and integrate it into their main anti-malware offering it seems that they've decided instead to treat it as and exciting new potential revenue stream and started charging money for it (not that i think there's anything wrong with charging money for a product, but if it's product-ready then why is it separate from the rest of their anti-malware offerings? or alternatively, if they're going to offer individual tools as well as suites, why aren't there more stand-alone tools?)... this fracturing of the anti-malware market comes at the expense of being able to communicate a clear and comprehensive message to the user/customer about anti-malware security.... without anything else to tell them how anti-malware security works (and for the most part there isn't anything else that regular people would be exposed to), the way the technologies themselves are presented implicitly communicates this to the user and fracturing your own set of offerings to make some extra green is a failure to properly manage this implicit message...
Tags:
anti-malware,
anti-virus,
symantec,
user education
Monday, December 31, 2007
user education from a different angle
this is rather old but back in september, mike rothman posted an introduction to security mike's guide to internet security and while i was reading it a light bulb went off in my head...
i'm not sure a book (the guide is an ebook he sells, though there's portal and blog associated with it) can really start the kind of grassroots security movement mike is aiming for... i think there are inherent barriers in the scenario that would inhibit that, in fact... for one thing, the security knowledge that is supposed to be the currency of that grassroots movement is bound to an artifact (the ebook) and that artifact's distribution is controlled (more or less) by a commercial business model (mike put effort into that book and rightly wants to get paid)... the end result is that people have to want the knowledge in that book.. they have to want it bad enough that they're willing to pay for and read the book and that means that to some extent mike is probably going to wind up preaching to the choir...
what really piqued my interest, however, was the question that came to mind of whether or not those barriers could be removed... obviously the book could be made free, that would be one barrier down, but the knowledge contained within it would still be bound to it... in order to get the knowledge you'd need to get the book and in order to pass on the knowledge you'd have to pass on the book... passing the knowledge on from one person to the next is clearly a requirement for mike's grassroots security movement, and in the broader context that security movement sounds an awful lot like the "culture of security" i've often heard we need... but culture tied to a book just doesn't seem like it would be successful now... it certainly was in the past when books and culture were inexorably linked, but that time ended long (on the order of centuries) ago... what if the information could be passed from person to person without the book? perhaps not all as one big chunk but rather piece by piece... what would that look like?
then it struck me - that would look like a meme... a unit of cultural information that replicates from one mind to another by way of imitation... so then i set about trying to learn more about memes (did anyone miss me in october?) because i didn't (and still don't, really) know all that much about them... what i found was that virtually all culture can be regarded as being memetic in nature, whether it be religion or consumerism, politics or littering (you didn't think memes were the exclusive domain of lolcats, did you?)... in fact, once you have an idea of what you're looking for you start being able to see it in all sorts of things...
as an aside, even going to school and reading books and learning things the old fashioned way are memetic, so you might be wondering why a security ebook wouldn't be just as successful... the reason has to do with the hook for the meme... up to a certain age you have to go to school, it's not even a choice, but if you want to be even moderately successful in later life you need to get good grades and not flunk out - which means reading the books and learning the material... later on, if you want an even better life, you enroll in post secondary education and read books and learn material so you can get your diploma, get a good job, and so on... what's in it for you as far as a security guide goes? do people generally want to learn about security? is it going to make a clear and obvious improvement in the quality of one's life? will there be frat parties along the way or hot guys/girls to chat up in class? no, a security guide doesn't have nearly as much going for it from a memetic hook point of view as academia does and academia isn't exactly the most successful meme either (just look at how relatively few participate in it compared to religion or tv watching, for example)...
another thing that i've learned is that in order to use memes to disseminate security knowledge (or at least promote more secure behaviour) it's going to be necessary to engage in memetic engineering in order to construct suitable memes - though i'm still looking for better sources for what's involved in meme synthesis and/or meme splicing because so far my best attempts have turned out to just be meme hacks... now, if you're thinking that memetic engineering sounds a bit like social engineering, well, you'd be right and the irony of using such a technique for good instead of evil is not lost on me... i suppose you could call it a kind of white-hat social engineering...
the more interesting bit of irony (to my mind at least) is that using memes to help people make themselves more secure against malware and other security threats means using something with similar properties to the most well known form of malware - viruses... indeed, memes have even been referred to as viruses of the mind... it is this very viral quality that i think needs to be exploited in order to reach a wide enough group of people to "suffocate the bad guys" (as mike put it) and bring about the "culture of security"...
i'm not sure a book (the guide is an ebook he sells, though there's portal and blog associated with it) can really start the kind of grassroots security movement mike is aiming for... i think there are inherent barriers in the scenario that would inhibit that, in fact... for one thing, the security knowledge that is supposed to be the currency of that grassroots movement is bound to an artifact (the ebook) and that artifact's distribution is controlled (more or less) by a commercial business model (mike put effort into that book and rightly wants to get paid)... the end result is that people have to want the knowledge in that book.. they have to want it bad enough that they're willing to pay for and read the book and that means that to some extent mike is probably going to wind up preaching to the choir...
what really piqued my interest, however, was the question that came to mind of whether or not those barriers could be removed... obviously the book could be made free, that would be one barrier down, but the knowledge contained within it would still be bound to it... in order to get the knowledge you'd need to get the book and in order to pass on the knowledge you'd have to pass on the book... passing the knowledge on from one person to the next is clearly a requirement for mike's grassroots security movement, and in the broader context that security movement sounds an awful lot like the "culture of security" i've often heard we need... but culture tied to a book just doesn't seem like it would be successful now... it certainly was in the past when books and culture were inexorably linked, but that time ended long (on the order of centuries) ago... what if the information could be passed from person to person without the book? perhaps not all as one big chunk but rather piece by piece... what would that look like?
then it struck me - that would look like a meme... a unit of cultural information that replicates from one mind to another by way of imitation... so then i set about trying to learn more about memes (did anyone miss me in october?) because i didn't (and still don't, really) know all that much about them... what i found was that virtually all culture can be regarded as being memetic in nature, whether it be religion or consumerism, politics or littering (you didn't think memes were the exclusive domain of lolcats, did you?)... in fact, once you have an idea of what you're looking for you start being able to see it in all sorts of things...
as an aside, even going to school and reading books and learning things the old fashioned way are memetic, so you might be wondering why a security ebook wouldn't be just as successful... the reason has to do with the hook for the meme... up to a certain age you have to go to school, it's not even a choice, but if you want to be even moderately successful in later life you need to get good grades and not flunk out - which means reading the books and learning the material... later on, if you want an even better life, you enroll in post secondary education and read books and learn material so you can get your diploma, get a good job, and so on... what's in it for you as far as a security guide goes? do people generally want to learn about security? is it going to make a clear and obvious improvement in the quality of one's life? will there be frat parties along the way or hot guys/girls to chat up in class? no, a security guide doesn't have nearly as much going for it from a memetic hook point of view as academia does and academia isn't exactly the most successful meme either (just look at how relatively few participate in it compared to religion or tv watching, for example)...
another thing that i've learned is that in order to use memes to disseminate security knowledge (or at least promote more secure behaviour) it's going to be necessary to engage in memetic engineering in order to construct suitable memes - though i'm still looking for better sources for what's involved in meme synthesis and/or meme splicing because so far my best attempts have turned out to just be meme hacks... now, if you're thinking that memetic engineering sounds a bit like social engineering, well, you'd be right and the irony of using such a technique for good instead of evil is not lost on me... i suppose you could call it a kind of white-hat social engineering...
the more interesting bit of irony (to my mind at least) is that using memes to help people make themselves more secure against malware and other security threats means using something with similar properties to the most well known form of malware - viruses... indeed, memes have even been referred to as viruses of the mind... it is this very viral quality that i think needs to be exploited in order to reach a wide enough group of people to "suffocate the bad guys" (as mike put it) and bring about the "culture of security"...
Tags:
memetics,
user education
Friday, December 28, 2007
what average users need to know
i read a very interesting post about average users and how they only care about usability to the exclusion of security and it got me thinking...
i think one of the main reasons people focus so much on usability and so little on security is because the threat is too abstract... they've heard of viruses (and so probably use anti-virus software, though probably don't update it) but the current threat landscape (as opposed to the one from 20 years ago that they are more familiar with) is too disconnected from the average person's day to day reality for them to comprehend the need for the security measures we more security conscious folks keep advising...
this is a problem, especially for those who advocate safe hex, so how do we address it?
one avenue we should probably consider is describing what threat a particular safe hex practice is meant to counter - but that only connects security measure with the threat, it doesn't actually make the threat itself seem any more real or anymore like something the user actually needs to worry about...
i think users might benefit from knowing what they have that attackers would want as well as what lengths attackers are willing to go to in order to get those things... what attackers would want from average users isn't a difficult list to compile (it may not be complete, but it certainly gets the point across):
what attackers are willing to do to get what they want isn't too hard to list either:
ultimately the average user needs to be made to understand that a computer is not an appliance that just does what they want it to (nor can it be), but rather it's a tool that can allow many people to do many things and not all people want to do good things... if they have stuff (money, personally identifiable information, data, etc) they want to keep safe then they need to care about security...
i think one of the main reasons people focus so much on usability and so little on security is because the threat is too abstract... they've heard of viruses (and so probably use anti-virus software, though probably don't update it) but the current threat landscape (as opposed to the one from 20 years ago that they are more familiar with) is too disconnected from the average person's day to day reality for them to comprehend the need for the security measures we more security conscious folks keep advising...
this is a problem, especially for those who advocate safe hex, so how do we address it?
one avenue we should probably consider is describing what threat a particular safe hex practice is meant to counter - but that only connects security measure with the threat, it doesn't actually make the threat itself seem any more real or anymore like something the user actually needs to worry about...
i think users might benefit from knowing what they have that attackers would want as well as what lengths attackers are willing to go to in order to get those things... what attackers would want from average users isn't a difficult list to compile (it may not be complete, but it certainly gets the point across):
- money
- credit card numbers for getting money
- personal identification information for getting new credit cards in your name so as to get money
- user names and passwords for financial institutions like banks or paypal so as to get money
- user names and passwords for any other site because you might be one of those people who uses the same user name and password everywhere and if so they can use that to get money
- cpu cycles, storage space, and bandwidth for attacking others, usually to get money from them
- fame and various other social rewards (though these are older goals that are much less relevant nowadays)
what attackers are willing to do to get what they want isn't too hard to list either:
- trick you (via social engineering) or your computer (via exploits) into installing malware to steal your credit card number, passwords, or any other information they can use
- trick you (phishing) or your computer (pharming) into believing a fake bank/paypal/whatever website is the real one so as to steal your account details or trick you into buying fictional goods - ultimately to steal your money
- trick you or your computer into installing malware to show unwanted advertisements (adware)
- trick you or your computer into installing malware that makes your data inaccessible until you pay a ransom
- trick you or your computer into installing malware to give the attacker enough access to your computer (generally making it part of a botnet) in order to use it to attack others (by trying to overload legitimate sites, hosting fake and/or exploit laden sites, sending junk mail, sending malware or links to malware sites, etc)
- trick administrators or systems at legitimate (and in some cases very popular) sites to host exploits for tricking the computers of visitors to those sites
- plant malware on or construct malware that can spread itself to removable media (floppy disks, cd's, dvd's, flash media, or basically anything with memory that you can plug into your computer)
ultimately the average user needs to be made to understand that a computer is not an appliance that just does what they want it to (nor can it be), but rather it's a tool that can allow many people to do many things and not all people want to do good things... if they have stuff (money, personally identifiable information, data, etc) they want to keep safe then they need to care about security...
Tags:
malware,
security,
user education
Wednesday, May 02, 2007
the effectiveness of user education
amrit williams has a post up about how ineffective user education is... if you've read this blog for a while you probably know how i feel about user education already but i guess there's more to say than to just point to anecdotal evidence of it working in real life (amrit does that himself with the example of his mother)...
so which is it? technological 'solutions' or user education, nature or nurture, particle or wave, fate or chance - to paraphrase forrest gump, it's a bit of both...
amrit is right that user education isn't going to make things secure, but let's look at that again - nothing is going to make things secure, not user education, not technological controls, not even a combination of the two... security isn't a boolean property, it's a gradient, talking about making things 'secure' is pure sophistry as we should be talking about making things more secure than they are right now... don't let the great be the enemy of the good; since perfection is impossible anyways one must settle for simply making things better...
in that vein user education has a rather well defined place... security requires intelligent, context-sensitive decision making that just can't be hard-coded into the system... i understand and appreciate that people are hard to control and generally unreliable... i understand why security folks would want to ignore the user problem since they're trying to build reliable security... unfortunately, whether we like it or not, users are a part of the system and they're always going to be a part of the system - technology cannot be an island unto itself, technological controls are just tools and users need to know how to use those tools properly or the tools themselves will be ineffective (just as knowledge without good tools is also ineffective)...
neither user education nor technological controls can reach their full potential on their own, they need each other if we're to get the most out of our attempts to make things more secure - and unreliable though that might be, it's better than relying on either individually...
so which is it? technological 'solutions' or user education, nature or nurture, particle or wave, fate or chance - to paraphrase forrest gump, it's a bit of both...
amrit is right that user education isn't going to make things secure, but let's look at that again - nothing is going to make things secure, not user education, not technological controls, not even a combination of the two... security isn't a boolean property, it's a gradient, talking about making things 'secure' is pure sophistry as we should be talking about making things more secure than they are right now... don't let the great be the enemy of the good; since perfection is impossible anyways one must settle for simply making things better...
in that vein user education has a rather well defined place... security requires intelligent, context-sensitive decision making that just can't be hard-coded into the system... i understand and appreciate that people are hard to control and generally unreliable... i understand why security folks would want to ignore the user problem since they're trying to build reliable security... unfortunately, whether we like it or not, users are a part of the system and they're always going to be a part of the system - technology cannot be an island unto itself, technological controls are just tools and users need to know how to use those tools properly or the tools themselves will be ineffective (just as knowledge without good tools is also ineffective)...
neither user education nor technological controls can reach their full potential on their own, they need each other if we're to get the most out of our attempts to make things more secure - and unreliable though that might be, it's better than relying on either individually...
Tags:
amrit williams,
security,
user education
Tuesday, February 28, 2006
user education is working
there is a fairly prevalent opinion in security circles that user education doesn't work... no matter how much you try to teach users, they never learn...
my retort to this is generally along the lines of "ok, give me your name, address, telephone number and credit card information and i'll prove you wrong"... obviously no one is going to give me that information and that proves them wrong - users of credit cards learned not to give that information out to every tom, dick, and harry a long time ago (we know they learned it because it's not knowledge they were born with)...
but sometimes that fails to convince, so here's a personal anecdote... i was out having a meal with some people not too long ago and the conversation briefly turned to email and the woman beside me (whom i had never met before and never coached in any way) said she tends to delete anything with an attachment... she was the first and only person to mention attachments during the brief discussion of email...
we're not talking about a security person or even necessarily a computer person here either - she's a school teacher and she's adopted a behaviour that was unheard of in the general populace 10 or even 5 years ago...
people never stop learning things, and netizens learn to adapt to the threats present in the environment they inhabit - how could they not? staying safe online is a competitive advantage and successful strategies will be discovered and adopted and spread like memes through the computer user population... they don't need to know the internals of how various threats operate or why certain safe-hex behaviours work, only that they do work...
my retort to this is generally along the lines of "ok, give me your name, address, telephone number and credit card information and i'll prove you wrong"... obviously no one is going to give me that information and that proves them wrong - users of credit cards learned not to give that information out to every tom, dick, and harry a long time ago (we know they learned it because it's not knowledge they were born with)...
but sometimes that fails to convince, so here's a personal anecdote... i was out having a meal with some people not too long ago and the conversation briefly turned to email and the woman beside me (whom i had never met before and never coached in any way) said she tends to delete anything with an attachment... she was the first and only person to mention attachments during the brief discussion of email...
we're not talking about a security person or even necessarily a computer person here either - she's a school teacher and she's adopted a behaviour that was unheard of in the general populace 10 or even 5 years ago...
people never stop learning things, and netizens learn to adapt to the threats present in the environment they inhabit - how could they not? staying safe online is a competitive advantage and successful strategies will be discovered and adopted and spread like memes through the computer user population... they don't need to know the internals of how various threats operate or why certain safe-hex behaviours work, only that they do work...
Tags:
email,
malware,
security,
user education
Subscribe to:
Posts (Atom)