CES Countdown #4: Who's securing the CE device's end user?

By Angela Gunn | Published January 5, 2009, 5:56 AM

CES 13 Coundown banner (300px)Computer security fuels many excellent conferences. CES is not typically one of them, but the current state of the economy is compelling conference goers to refocus on their core priorities...and security is one of them.

Some readers will argue that if we're talking about the best possible security for end users, we're at the wrong show -- Macworld's a little to the west. But as security researchers proved when they spanked OS X at last spring's CanSecWest conference, the world is moving on from the impenetrable-Apple era.

The issue for consumers at this point is simply to take security seriously -- get protection, keep it current, and use common sense when the Nigerian princes and m4k3-mon3y-f4$$$t crowd sends e-mail. Alas, neither CES nor anything other than direct exposure to the consequences is apt to change the habits of consumers who aren't already open to the message.

Many consumers might expect more security protection from their ISPs, especially in an era when cable boxes, HDTVs, and even more basic appliances sport their own IP addresses. The problem is that any sense of responsibility providers might feel in that direction is swamped by another "security" concern -- that of media companies that feel that ISPs and even hardware manufacturers are responsible for securing digital handcuffs on content.

It has been a full year since widespread coverage emerged of Vista's thuggish HDMI implementation. Frankly, 2008 wasn't exactly a big year for raising consumer consciousness of digital rights management issues, and though a couple of panels are slated for CES 2009 this week, you'd have to be wonderfully sunny-minded to think that ISPs are paying one-tenth the attention to saving Joe Enduser from the botnet hordes that they are to keeping various DRM-desiring concerns (and their respective lawyers) at ease with ever-faster bandwidth offerings.

One more thing consumers can do to embiggen their security in 2009? Keep a close eye on Congress and the White House. A slew of stories throughout 2008 indicated that the incoming crop of politicians merit a watchful eye from security- and privacy-conscious Americans. (Not that the last didn't, but we're looking ahead here, not behind.) The President-Elect is computer-friendly, but that doesn't necessarily translate to greater security and privacy protections for citizens. As corporations accede to customer pressures to anonymize data more quickly, expect the feds to request both longer periods of data retention and more data retention by ISPs.

The picture's more nuanced on the enterprise side, where budget cuts and a treacherous economy are putting pressure on security spending exactly when certain folk might be most tempted to ill-gotten gains. Again, follow the money: An infosec pro whose system is hacked is apt to be fired or otherwise adversely affected, whereas an end user whose system is hacked has very little financial recourse to punish an allegedly security-lax ISP. (Especially if the problem stems from something the user clicked or installed with his own two typing fingers.)

That said, some infosec professionals are warning that a lot of businesses are slacking on protection -- even legally mandated protection -- figuring it's better to solve a problem (clean up a hack, pay a fine) in 2010 than to go broke in 2009.

The chaotic IT environment during mergers and acquisitions (so popular among strong companies when rivals are struggling) means that even relatively hardened targets can become soft for the patient and clever hacker. One expert we talked to characterized some security-poor companies as having crossed fundamental safety lines, even blowing off compliance with standards that don't have an immediate bottom-line impact (e.g., SOX).

"You used to see companies pushing risk into their next budget cycle, covering themselves in the present and pushing speculative risk into the future," our source said. "Now the pressure just to survive the current budget cycle means some risks that were previously unacceptable are going untreated."

What to do, what to do? Joel Scambray, author of Hacking Exposed: Network Security Secrets & Solutions and CEO of Seattle-based security consultancy Consciere, says that smart companies will make it through the haze by sticking with the fundamentals. "Understand the business you're in, define achievable goals, review progress against them periodically, and hold people accountable -- for successes as well as failures," he says. "Good infosec fundamentals, like thrift, diversification, and saving, are once again back in vogue."

Scambray even sees a few trends that bode well for security beyond the current climate. Firms are beefing up detective and reactive infrastructure, including security-event information management and forensics capabilities, "because many enterprises have learned the hard way that an ounce of preparation is worth a pound of cure." He sees ongoing "housebreaking" of application software development, editing the process into manageable and thus securable practices.

There's also a return to fundamentals -- reviewing and refining internal security procedures, developing meaningful security metrics that align with organizational objectives, and managing compliance-and-audit fatigue with "sensible programs that meet well-established standards of 'due care,'" standards that can even be extensible to third parties.

And, Scambray says, candor with stakeholders is key. Even though, as he puts it, "as we've witnessed again recently with the Madoff fraud, a secretive smile and the wisp of something exclusive can fool even the most sophisticated," the current austere mood means that pragmatic security talk can "win friends and convert enemies for the information security profession." The times may be hard, but maybe that means that businesses are ready to hear hard security truths.

Now, can someone convince the civilians not to answer those e-mails from the Nigerian princes, and convince the ISPs that consumers care about more than just the fastest possible bandwidth?

Comments

View comments by with a score of at least

Nice to point out that there's a diminishing difference between consumer electronics and computing devices. Mobiles and laptops have converged in most aspects except display size, and the set-top box is close to becoming the desktop computer. Yeah, security matters, and it ain't coming from the ISP for *any* of these connected consumer devices.

Score: 0

|

PDC 2009: What have we learned this week?

There was the freebie that no one will forget, the heebie-jeebies courtesy of Scott Guthrie, and a teensy bit clearer picture of how this cloud thingie should work.

Live report: Will Google Chrome OS change Linux?

The mysteries of just what Chrome OS is, and how much of an operating system it truly is, may be resolved today.

PDC 2009: Microsoft cares about Web browser performance

The effort to give users of the world's dominant Web browser the impression of quality, is a personal one for the man who leads that battle.

Nokia re-affirms its commitment to Symbian, sort of

Maemo won't necessarily be replacing Symbian in the Nokia N-Series, but that's definitely a place where it will be found.

E-book readers will be in short supply this holiday season

E-readers are hot this year, and a lot of compelling new products have been released, but are there enough electrophoretic displays to go around?

Sony looks to finally open a single storefront for downloads

Sony has had many different download portals for movies, music, e-books, and games, and now it's looking to make a single shop for all of it.

Tuning out the tablet: Time to give the endless speculation a rest

Wide Angle Zoom: Wishing and hoping and thinking and praying....won't put an iTablet on the market.

Five improvements for IT managers in 2010

If businesses are to improve their efficiency for next year, they need to stop and reassess the basic tenets of their job.

AOL's spinoff from Time Warner to shed 2,500 jobs

As AOL moves toward become an independent company again, it will cut nearly a third of its workforce.

Gartner: SMS-based money transfer will be bigger than mobile browsing, search

Gartner issues its predictions for the 10 things our phones will be doing in 2012.

Don't forget to upgrade to Firefox 3.6 beta 3 today

Mozilla has released the latest beta its Firefox 3.6 browser software, just over one week after beta 2.