Re: No .1 Security Problem in the World

From: David Bianco (bianco@jlab.org)
Date: 06/27/02


From: David Bianco <bianco@jlab.org>
Date: 27 Jun 2002 15:05:15 -0400

john.veldhuis@universal.nl writes:

> I'm interested to know from people that consider themselve security
> experts, what they consider to be the most important Problems in the
> realm of Computer Security.
>
> IMHO:
> Management and user awareness, security conscienceness, or whatever you
> want to call it.

This is closely related, but I think lack of vendor committment is one
of the biggest problems with securing systems today. I say it's
related because vendors won't really address the problem until
customers demand security, and customers won't demand it if they
don't know what to demand.

-- 
David J. Bianco, GSEC		<bianco@jlab.org>
Thomas Jefferson National Accelerator Facility

The views expressed herein are soley those of the author and not those of SURA/Jefferson Lab or the US DOE.



Relevant Pages

  • Re: Help...Where should I start?
    ... >> demand, as are those who can do the same for web apps. ... > Ben, I've considered your advice, and while I'm sure the intent here is to ... > to specialize in C++ security code. ... > criminal like every other successful business person and cheating on the ...
    (microsoft.public.cert.exam.mcse)
  • Re: Help...Where should I start?
    ... > demand, as are those who can do the same for web apps. ... Ben, I've considered your advice, and while I'm sure the intent here is to ... criminal like every other successful business person and cheating on the ... Website security is pretty simple: Don't put anything on the web that isn't ...
    (microsoft.public.cert.exam.mcse)
  • Re: Where is it all going?
    ... Excerpt from Bank glitch leaves 10 million Canadians without paycheque ... strengthening their security measures while trying to mitigate risk. ... The above demand is just in banking domain, ... >> IT in finance sector is ...
    (microsoft.public.cert.exam.mcse)
  • Re: Code security newbie
    ... Declarative security may be easier to use, since you don't have to create new objects, and demand them at run time. ... >>>X-Newsreader: Microsoft Outlook Express 6.00.3790.0 ...
    (microsoft.public.dotnet.security)
  • Re: Securing .DLLs from other applications
    ... this does provide so little security that in 2.0 these checks are ... > Assembly.Load(string,Evidence) and passing your evidence; ... > full Demand in a reflection scenario) stack walk will fail the call as ...
    (microsoft.public.dotnet.security)