Security Incidents mailing list archives

Re: Novarg


From: Matt Curtin <cmcurtin () interhack net>
Date: Thu, 29 Jan 2004 18:31:06 -0500

"Greg A. Woods" <woods () weird com> writes:

No, the _best_ defense against viruses and worms, especially the e-mail
borne ones, is to not allow your users to run known vulnerable software
in the first place.

[...]

Any user stupid enough to jump through all the hoops which would be
necessary to manually execute an attachment deserves what they get.

This isn't likely stupidity, but in fact ignorance.  Thus the need for
training.

[This is the end of my remarks directed to Greg; the rest is much more
general, for all of us, including myself.  Yes, I talk to myself
frequently.] 

People make mistakes.  Software fails.  We should design our systems
understanding these truths, so that when either condition takes place,
we handle the condition as gracefully as we can.

Yes, I hate Microsoft "LookOut!" as much as anyone else, but the
problems that we're facing are much more complex.  People have
improper expectations -- that they should be able to sit in front of
something and without having invested three minutes into understanding
the tool or the task, start Doing Stuff.  This is utter nonsense.

We do have much better software available -- I use Gnus -- but these
systems that are more sophisticated, make users more productive, and
treat data with the proper level of safety will require more user
training than those that try to figure out what the user really wants,
thus "helpfully" doing things like automatically opening attachments,
executing macros, and the like.

People cannot be expected to understand something if no one has taken
the time to explain to them that the lowest cost of entry or the most
shallow learning curve is only the beginning, and ultimately a very
small part of the experience of using something over a lifetime.

If we're so very clever and The Users are so very stupid, why is it
that we, who ultimately control all of this crap, cannot keep it from
biting us in the butts?

Bitching about users solves nothing.  We need to shut up and do
something productive.

Articulating requirements that include security requirements and
refusing to allow software that fails to meet them is a good start.
But ultimately, unless we help people to see things differently, to
try to understand what they're doing before they attempt it, we're
just dealing with one kind of problem, while leaving unaddressed
another.

-- 
Matt Curtin, CISSP, IAM, INTP.  Keywords: Lisp, Unix, Internet, INFOSEC.
Founder, Interhack Corporation +1 614 545 HACK http://web.interhack.com/
Author of /Developing Trust: Online Privacy and Security/ (Apress, 2001)

---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: