News
Commentary
10/25/2005
02:17 PM
Commentary
Commentary
Commentary
Connect Directly
RSS
E-Mail
50%
50%

Security Myths That Need To Be Put To Rest

As columnist Wayne Rash points out, conventional wisdom about security can be a useful guide--or a trap.

5. Spam may be annoying, but it’s not a security threat.
This depends on the spam, and on what you consider a security threat. Some spam contains a payload of worms, viruses or other malware or phishing content. In addition, some comes with content that can get you sued if you don’t attempt to stop it, such as graphical ads for porn sites. And even if none of that happens it can bog down your network, fill up your servers and suck up your bandwidth.

6. My wireless network is secure as long as encryption is turned on.
Encryption, even the outmoded WEP encryption that comes with 802.11b, is certainly better than nothing. But unless you’ve changed to the much more secure WPA encryption, turned off SSID broadcasts from your access points, and required an authenticated logon for wireless users, you’re still vulnerable.

7. Moving to biometrics will make my network more secure.
Perhaps. Biometric readers are a popular new feature for corporate and high-end consumer users. The idea is that you can use your fingerprint instead of a password. After all, everyone’s fingerprints are unique, right? That part is true – the unique nature of individual fingerprints is well proven. Unfortunately, affordable biometric devices are not overly reliable, fingerprint readers on laptops and keyboards are rife with false negatives, and there’s always the problem if having a Band-Aid on your finger. This means that you’ll have to set up an alternate means of getting access to a device using biometrics, and that means you’re back to passwords. Of course, there are biometric readers that are quite good, but almost no company can afford those for use on every desktop and laptop computer.

8. Full-disk encryption on workstations and laptops will protect my data against unauthorized access.
Probably not. Most full-disk encryption software only protects computers that happen to be turned off at the time. When they’re turned on, everything is automatically decrypted when read, and delivered to anyone with access to the computer. If you’re afraid of your laptop being stolen, full disk encryption will keep the data from being read as long as it’s stolen while turned off. But it probably won’t protect at all against someone logging in to your computer remotely while it’s attached to the network.

9. I can change to Linux for everything and be more secure.
It’s true that there are fewer viruses and worms aimed at Linux, but if you take a look at the SANS Institute / FBI top 20 vulnerability list, you’ll see that the problems of Linux and Windows are about equal. And the prime cause for security problems – complacency – is the same for both operating systems. There’s no security edge there.

10. My best security investment is in training.
This one happens to be true. Unless your users and administrators are properly trained, and that training kept up to date, your other efforts are diminished if not simply wasted. After all, you’re a lot better off if people remember not to open attachments than you are if you have to launch an AV program because someone did open something bad that came in the mail. But for your users to know this, they must be trained.

Previous
2 of 2
Next
Comment  | 
Print  | 
More Insights
IT's Reputation: What the Data Says
IT's Reputation: What the Data Says
InformationWeek's IT Perception Survey seeks to quantify how IT thinks it's doing versus how the business really views IT's performance in delivering services - and, more important, powering innovation. Our results suggest IT leaders should worry less about whether they're getting enough resources and more about the relationships they have with business unit peers.
Register for InformationWeek Newsletters
White Papers
Current Issue
InformationWeek Must Reads Oct. 21, 2014
InformationWeek's new Must Reads is a compendium of our best recent coverage of digital strategy. Learn why you should learn to embrace DevOps, how to avoid roadblocks for digital projects, what the five steps to API management are, and more.
Video
Slideshows
Twitter Feed
InformationWeek Radio
Archived InformationWeek Radio
A roundup of the top stories and trends on InformationWeek.com
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.