CES Countdown #4: Who's securing the CE device's end user?

By Angela Gunn | Published January 5, 2009, 5:56 AM

CES 13 Coundown banner (300px)Computer security fuels many excellent conferences. CES is not typically one of them, but the current state of the economy is compelling conference goers to refocus on their core priorities...and security is one of them.

Some readers will argue that if we're talking about the best possible security for end users, we're at the wrong show -- Macworld's a little to the west. But as security researchers proved when they spanked OS X at last spring's CanSecWest conference, the world is moving on from the impenetrable-Apple era.

The issue for consumers at this point is simply to take security seriously -- get protection, keep it current, and use common sense when the Nigerian princes and m4k3-mon3y-f4$$$t crowd sends e-mail. Alas, neither CES nor anything other than direct exposure to the consequences is apt to change the habits of consumers who aren't already open to the message.

Many consumers might expect more security protection from their ISPs, especially in an era when cable boxes, HDTVs, and even more basic appliances sport their own IP addresses. The problem is that any sense of responsibility providers might feel in that direction is swamped by another "security" concern -- that of media companies that feel that ISPs and even hardware manufacturers are responsible for securing digital handcuffs on content.

It has been a full year since widespread coverage emerged of Vista's thuggish HDMI implementation. Frankly, 2008 wasn't exactly a big year for raising consumer consciousness of digital rights management issues, and though a couple of panels are slated for CES 2009 this week, you'd have to be wonderfully sunny-minded to think that ISPs are paying one-tenth the attention to saving Joe Enduser from the botnet hordes that they are to keeping various DRM-desiring concerns (and their respective lawyers) at ease with ever-faster bandwidth offerings.

One more thing consumers can do to embiggen their security in 2009? Keep a close eye on Congress and the White House. A slew of stories throughout 2008 indicated that the incoming crop of politicians merit a watchful eye from security- and privacy-conscious Americans. (Not that the last didn't, but we're looking ahead here, not behind.) The President-Elect is computer-friendly, but that doesn't necessarily translate to greater security and privacy protections for citizens. As corporations accede to customer pressures to anonymize data more quickly, expect the feds to request both longer periods of data retention and more data retention by ISPs.

The picture's more nuanced on the enterprise side, where budget cuts and a treacherous economy are putting pressure on security spending exactly when certain folk might be most tempted to ill-gotten gains. Again, follow the money: An infosec pro whose system is hacked is apt to be fired or otherwise adversely affected, whereas an end user whose system is hacked has very little financial recourse to punish an allegedly security-lax ISP. (Especially if the problem stems from something the user clicked or installed with his own two typing fingers.)

That said, some infosec professionals are warning that a lot of businesses are slacking on protection -- even legally mandated protection -- figuring it's better to solve a problem (clean up a hack, pay a fine) in 2010 than to go broke in 2009.

The chaotic IT environment during mergers and acquisitions (so popular among strong companies when rivals are struggling) means that even relatively hardened targets can become soft for the patient and clever hacker. One expert we talked to characterized some security-poor companies as having crossed fundamental safety lines, even blowing off compliance with standards that don't have an immediate bottom-line impact (e.g., SOX).

"You used to see companies pushing risk into their next budget cycle, covering themselves in the present and pushing speculative risk into the future," our source said. "Now the pressure just to survive the current budget cycle means some risks that were previously unacceptable are going untreated."

What to do, what to do? Joel Scambray, author of Hacking Exposed: Network Security Secrets & Solutions and CEO of Seattle-based security consultancy Consciere, says that smart companies will make it through the haze by sticking with the fundamentals. "Understand the business you're in, define achievable goals, review progress against them periodically, and hold people accountable -- for successes as well as failures," he says. "Good infosec fundamentals, like thrift, diversification, and saving, are once again back in vogue."

Scambray even sees a few trends that bode well for security beyond the current climate. Firms are beefing up detective and reactive infrastructure, including security-event information management and forensics capabilities, "because many enterprises have learned the hard way that an ounce of preparation is worth a pound of cure." He sees ongoing "housebreaking" of application software development, editing the process into manageable and thus securable practices.

There's also a return to fundamentals -- reviewing and refining internal security procedures, developing meaningful security metrics that align with organizational objectives, and managing compliance-and-audit fatigue with "sensible programs that meet well-established standards of 'due care,'" standards that can even be extensible to third parties.

And, Scambray says, candor with stakeholders is key. Even though, as he puts it, "as we've witnessed again recently with the Madoff fraud, a secretive smile and the wisp of something exclusive can fool even the most sophisticated," the current austere mood means that pragmatic security talk can "win friends and convert enemies for the information security profession." The times may be hard, but maybe that means that businesses are ready to hear hard security truths.

Now, can someone convince the civilians not to answer those e-mails from the Nigerian princes, and convince the ISPs that consumers care about more than just the fastest possible bandwidth?

Comments

View comments by with a score of at least

Nice to point out that there's a diminishing difference between consumer electronics and computing devices. Mobiles and laptops have converged in most aspects except display size, and the set-top box is close to becoming the desktop computer. Yeah, security matters, and it ain't coming from the ISP for *any* of these connected consumer devices.

Score: 0

|

EC's Kroes to US senators: Mind your own business on Oracle + Sun

If the AP is accurate, the EU's antitrust chief just told the United States Senate that any merger that takes place in the world is more her affair than theirs.

What does AT&T's 'Mark the Spot' app say about service quality?

That's a question for Betanews readers to answer in comments to this post.

Windows fix for TLS security bug still forthcoming, won't be Tuesday

Anyone looking for a fix for last month's discovery of a potentially serious security hole in TLS and SSL may have to wait until everyone is ready to act together.

Google rolls out real-time search, Near Me Now, extended personalization

Over time, searches from PCs and mobile phones will grow even "more personalized." But what about user privacy and search results that give you "the truth"?

Betanews Podcast: Rupert Murdoch and the buying stuff online problem

We'll have a more difficult time paying for online news if the underlying protocol for online payment has a big gaping hole in it.

Not the first, not the last, technology predictions for 2010

Carmi Levy | Wide Angle Zoom: The real truth is probably that what went around in 2009, will come around to haunt us next year.

Google Goggles: Hands on with the Shazam of the Real World

Google today unveiled Goggles, its visual search lab for Android devices that identifies objects by sight.

Microsoft: Windows 7 Family Pack wasn't 'pulled,' it just sold out

If you hurry, you may still be able to find the last Family Pack upgrade editions hanging around retail store shelves, but probably not so much online.

Clever iPhone game returns after being bumped over a name dispute

The game's simple concept and multitude of platforms and puzzles manage to pull off a retro, 8-bit style that's reminiscent of an old Atari game given a modern makeover.

Intel's marriage of CPU and GPU not ready for prime time

Although there will be an Intel component this month that can compute and plot in parallel, Betanews was told today, it won't be based on Project "Larrabee."

An alternative to Research in Motion's enterprise e-mail? There's an app for that

Good Technology today released an iPhone app compatible with its enterprise e-mail solution.