USENIX LISA: Security Theater Plays a Role - Bruce Schneier's Keynote
The opening keynote Thursday of the USENIX LISA conference in San Diego was by author and security expert Bruce Schneier. In his opinion "perceived security" should be an aspect of all security implementation.
The large conference room was packed at Schneier's presentation, "Reconceptualizing Security." In one of his first slides, he pointed out that security has always been one of the basic human instincts by showing the part of the brain known as the amygdala where the emotion of fear (and its opposite, security) is seated. Schneier joked that "the newer part of the human brain responsible for heuristics is still in beta." He undermined the discrepancy between subjective feelings and provable facts with a few examples. Deviating from his slides and presentation material, he relied mainly on his words and gestures. "Security is at one time feeling and reality," according to his thesis, "You can feel safe without actually being safe, and you can feel unsafe for no apparent reason."

Schneier applied his thesis to a phenomenon he called "security theater." As an example he used the safety screw cap, designed to quell any fear that the content of the bottle might have been tampered with. He could think of at least ten ways that the content could be compromised, mentioning a syringe for one. Nevertheless, tamper-proof bottles provide an objective sense of security, which proved a saving grace for the medication industry after some well known poisoning incidents. Schneier felt that "as technicians, we kid ourselves that the security for which we're responsible is reliabable. That isn't true. We forget that humans play a major role."
Ignoring the emotional part of security is wrong in Schneier's judgment, and he advises technicians to incorporate the "security theater" concept in their work. Responding to a question about statistics, he suggested that they have little effect: "People who know statistics think they work better, but they don't." According to him, security models should adhere closely to reality, while recognizing that reality is mutable. His conclusion: "It's only when the feeling and the reality of security converge that we have real security."
Issue 220/2019
Buy this issue as a PDF
News
-
Kali Linux 2019.1 Released
The favorite Linux distro of Mr. Robot gets the first update of 2019.
-
Linux Foundation Releases a New Draft of OpenChain Spec
OpenChain provides a standard for open source compliance throughout the software supply chain.
-
Linux Kernel Continues To Offer Mitigation for Spectre Mitigation
Kernel 4.19 has added another family of Spectre vulnerabilities to its list of mitigating the mitigation.
-
SpeakUp Trojan Targets Linux Servers
It’s exploiting a known vulnerability.
-
KDE Plasma 5.15 Beta Arrives
Major improvements to software management.
-
Canonical Announces Latest Ubuntu Core for IoT
Now offers 10 years of support.
-
GitHub Offers Free Private Repositories
Popular source code collaboration site makes a major change to feature set.
-
Linus Torvalds Welcomes 2019 with Linux 5.x
Better support for GPUs and CPUs.
-
Keep your edge with these powerful Linux administration tools:
Keep All Your Linux Servers in Check
Watching the Bad Guys with Cowrie
Become a certified Linux Admin professional with the Linux Professional Institute LPIC-1 Systems Administrator certification.
-
Microsoft Gets an Open Source Web Browser
The company will use Google Chromium web browser as the foundation for its next browser.