Human Error Is Greatest Security Risk
from the no-surprise-there dept
For all the talk about "trustworthy computing" and how buggy software is a big "cybersecurity" risk, it turns out (and, no, this shouldn't surprise you), that the biggest security risk remains human error - and not security holes in software. People simply configure things wrong and leave security wide open all the time. While there's nothing wrong with promoting better software, it might be more productive to better train IT workers in properly securing systems.
4 Comments | Leave a Comment..
If you liked this post, you may also be interested in...
- How Being More Open, Human And Awesome Can Save Anyone Worried About Making Money In Entertainment
- Evidence Shows That Megaupload Shutdown Had No Real Impact On Infringement
- DailyDirt: Anthropomorphizing Animals
- DailyDirt: Birds Do The Darndest Things
- iPhone Data Debunks Recording Industry's Report On How French Three Strikes Law Increased Sales





Reader Comments (rss)
(Flattened / Threaded)
Astonishing
[ reply to this | link to this | view in thread ]
hmmmm, then why is it that..
Sounds like someone wants more money. In an economy that's hurting and lacking job I can see where certifying agents would be "alarmed", their life's bread is dwindling.
[ reply to this | link to this | view in thread ]
Re: Astonishing
Excellent point. I should have noticed that...
[ reply to this | link to this | view in thread ]
Bull!?!
Yes, stupid mistakes by administrators setting up computers do happen, and sometimes they mess the machine up enough that an attacker can access their system... I've been on many an assessment where we busted root in a server because the administrator did the wrong thing, and many a DefCon CTF where the same occurred, but to find these vulnerabilities takes an attacker of far more caliber than your normal script kiddies who pound Unix boxes with Windows exploits.
And besides, education trumps these types of errors, but looking at Microsoft for experience, very little is accomplished when you try to teach programmers to do the right thing, but don't have any real code review process in place. I'd take computers with OpenBSD on them, administered by clueless newbies over Windows boxen administered by the best of the best any day.
Then again, I have the best of the best running OpenBSD....
[ reply to this | link to this | view in thread ]
Add Your Comment