During his Tuesday keynote at the RSA Conference 2006, Sun Microsystems CEO Scott McNealy said the bar is low regarding security in the technology market. "The computer industry is more screwed up than any industry except health care, which kills everyone eventually," he said. More specifically, McNealy criticized large, cobbled-together data centers that don't make use of standardized protocols to communicate and verify information. McNealy also pointed out that PC security is suffering for the exact opposite reasons, namely that most people use the same type of device and operating system, "the same DNA," which makes them easier to attack.
McNealy also announced that the Sun Java System Web Server 7.0, due for release this summer and part of the Sun Java Enterprise System, would support Elliptic Curve Cryptography, which is used by the National Security Agency to protect classified government information. By including ECC in the Java System Web Server, Sun is looking to cut the time it takes to complete secure online transactions.
Microsoft is in complete agreement that users need to simplify security in order to make it easier to use and more ubiquitous. "We have an overly complex situation today" for end users, IT workers, and application developers, Microsoft chairman and chief software architect Bill Gates said during his Tuesday keynote. Such complexity hinders adoption of security.
Microsoft's vision of simplicity in security includes the company's upcoming "network access protection" for ensuring that devices looking to connect into a network are free from viruses or other contaminants. The feature can place PCs and laptops running Windows Vista and connected to servers running Microsoft's upcoming Windows Server software code-named Longhorn, into special "quarantine zones" until they're furnished with updates that bring them into compliance with a company's PC-health policies. Another technology that's key to Microsoft's vision of "trustworthy computing" is the InfoCard, which stores user information on the PC and can be used to authenticate that user during online transactions. Multi-factor authentication needs to be "built down into the system itself," Gates said.
Yet companies need to figure out the specific level of authentication required for a particular transaction. Can a user remain anonymous to the system, or should their identity be verified in depth? Or can a "pseudonymous" identification be employed to reduce complexity while at the same time providing acceptable levels of security?
Not a fan of a one-size-fits-all approach to authentication, RSA Security Inc. president and CEO Art Coviello said during his Tuesday keynote, "Businesses need to embrace an adaptive approach to authentication." He likens the online world to a "crime-ridden neighborhood" that requires companies conducting business there to stay ahead of their adversaries.
Smaller transactions can be protected using passive authentication methods that simply compare a user's behavior, i.e., the transactions they're initiating, with past behavior. Any anomalies can trigger alerts to a security team or shut down a transaction before it can be completed. Larger transactions require active authentication in the form of tokens, smart cards, and USB-pluggable devices that contain information used to authenticate the user to the transactional system.
Such a proactive approach to security is necessary because "the opponent is not standing still," Gates said. Businesses have to move to smart cards, InfoCards, and support for standards. "We're really at the beginning of this trust ecosystem," Gates said, who added that he is seeing progress. More and more users are updating their Windows systems regularly to get the latest features and security components. In fact, 80% of Windows users take advantage of regular Windows updates, compared with only 50% a couple of years ago.
Achieving Successful Coexistence Between Notes and Microsoft Platforms
Learn about the key migration and coexistence challenges youżll face when considering migration from IBM Lotus Notes to Microsoft Exchange and Microsoft SharePoint Server. Get best practices for planning and executing a successful coexistence strategy, and discover how you can ensure seamless coexistence between the Lotus and Microsoft environments.
NOTE: Offer valid for U.S., U.S. possessions, & Canada only.