The InformationWeek -- Blogs

Microsoft

Topics:   Microsoft

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

The Klondike Bar Problem


Posted by Dave Methvin, Nov 8, 2009 09:40 PM

During the 19th century, P. T. Barnum supposedly said, "There's a sucker born every minute." In the 21st century, those suckers now fall for PC-based scams. In the process, they hurt more than just themselves or their PCs.


The title of this blog entry refers to a long-running series of ads for Klondike Bar ice cream sandwiches. Various people are asked what they would do for a Klondike Bar; it turns out they are willing to do all sorts of embarrassing, demeaning and just plain silly things for a two-dollar frozen confection. It's not just in ads though, the same thing happens in real life. Year after year, studies show that people are willing to give away personal data -- including passwords -- to strangers, in return for a chocolate bar or a chance to win a trip.

Of course, scams have been going on since Adam met Eve, but with computers it's easy to do it on a global and massive scale. The possibilities for fraud are endless: spam, phishing, Nigerian banking schemes, spyware, system hijacking, identity theft, corporate espionage -- you name it. It is effective, and in general it's been easy for the bad guys to get away with it. Since it works, criminals continue to do it and expand their scale to increase the profitability.

Every new craze has its abusers, and it takes a while for any type of regulation or reason to catch up with the scammers. A few years back, the big problem was adware and spyware that inundated users with advertising and stole money from legitimate advertisers. Now the questionable business practices have moved on to new ground like Facebook applications. Michael Arrington has been exposing the ugly underside of how these games are funded. It boils down to dumb users, which of course is a proven and profitable business model.

Since users making bad decisions are the weakest link in the security chain, it also follows that gullible users can hurt an organization whether they use Windows PCs, Macs, Linux, or mobile devices. Strict policies can help, for example to say what software can be used on a company computer. Yet users often don't realize they're violating policies, especially the ones who fall for social engineering scams.

So what measures can a company take to reduce their risks here? If the past is any indication, regulation or law enforcement can't effectively address these emerging threats. One possible defense is to fight with sofware -- lock down the PCs so that only approved applications are installed and no other software can run, but not all users can handle a leash that short. Education is another step to consider; the more users know about the dangers out there, the better they can respond. Maybe they will be willing to learn about these dangers if you give them a Klondike Bar.

« JailBroken iPhones Targeted By Rick-Rolling Worm | Main | Verizon Attacks iPhone With Holiday Ads »



Sign Up Now
For InformationWeek News Alerts




This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




 
 

  1. Detecting Scalability Problems With Intel Parallel Universe Portal
  2. Just Say No To SFAQL Parallelism
  3. QuickThread: A New C++ Multicore Library


Join The InformationWeek Group On LinkedIn


                           


  1. Thoughts On The Motorola Droid
  2. Specs For Next Motorola Android Phone Leak
  3. Encryption Is Cloud Computing Security Savior


  1. Microsoft Bing Cashback Not Always A Bargain
  2. Google Buys Ad Start-Up Teracent
  3. Feds Launch Health IT Blog
  4. Full Nelson: Video: San Francisco Goes Open, Transparent
  5. AOL Previews Brand, Trims Workforce
  6. Physicians Question Health IT Stimulus Requirements

 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  DECEMBER 2008
NOVEMBER 2008
OCTOBER 2008
SEPTEMBER 2008
AUGUST 2008
JULY 2008
JUNE 2008
MAY 2008
  APRIL 2008
MARCH 2008
FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007