Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts

Friday, September 08, 2023

Cybersecurity

When deciding on the level of cybersecurity rules to enforce, there is always a tradeoff between security and cost (money and more importantly workplace efficiency). Since 100% cybersecurity is not possible, risk tolerance becomes important.

The first step of cybersecurity is identifying the threat: Are you trying to prevent middle school kids from gaining root access to your servers or do you have national security agencies in mind? Are you trying to prevent data leakage or data corruption? If you want to minimize leakage, is your data really worth the protection cost? People confuse value with secrecy. Something valuable does not make it automatically secret. Many things in life are valuable but not secret. In my experience, the real secrets are far less than what is commonly claimed. Classifying threats and security levels requires individuals who are both experts in security and are aware of its costs. Good luck finding them. Your typical security advisor has a vested interest in scaring you enough to sell you expensive products.

Risk averse managers lean on more and stricter rules. Managers become risk averse when the expected value of taking risks is low for them personally, i.e. when managers are punished when a risk is realized but not rewarded enough when the benefits of taking risks are reaped. In other words, when loyalty is more important than competency.

What is worse is that stricter rules may create the illusion of security (Security Theater) but can actually decrease it. For example, if you force employees to change their passwords every week, they will use more predictable passwords and even write them on Post-its and attach them to the side of their screens!

In such an environment, the cost of lower efficiency almost never comes up in management meetings and that cost is passed on to the lower level managers and engineers. If you are a software developer, your build times increase and sometimes fail. You have to spend a week to find out that the security software was blocking it, and inform the IT department to make an exception for your build. Since software is an ever changing field, you face such problems regularly. If there is a security breach, individuals are held responsible and the system is never questioned. In the long run, this causes longer shipping times, low quality, low morale and loss of personnel. In short, less security and less value to secure...

You have to make peace with the fact that a security breach will eventually happen, similar to earthquakes. What I propose is to use a minimal set of malware scanners and to focus on preventing data corruption by having good backup systems in place. Regulary check that you can build back your system from those backups so that a corruption will have minimal impact.

For more, see my previous posts.

Monday, November 03, 2008

Kitap önerileri

Beğendiğim kitaplardan bir kuple, okunmasını tavsiye ederim. Hepsinin ortak noktası etrafımızda olup biteni daha iyi anlamamızı sağlayacak bilgiler sunmaları.

Complications:

Atul Gawande isimli bir cerrah tıbbi konuları gerçek olaylardan yola çıkarak analiz ediyor. Tecrübesiz doktorların eğitimi adına hastalar ne kadar riske atılmalı, doktor hataları nasıl ele alınmalı, hasta kendisi ile ilgili tıbbi kararlarda ne kadar pay sahibi olmalı gibi hayati soruları tartışıyor. Heyecanlı ve eğlenceli. Tıp camiasını anlamak için mutlaka okunmalı, eninde sonunda hepimiz onların eline düşeceğiz çünkü.
[p.7] [Medicine] is an imperfect science, an enterprise of constantly changing knowledge, uncertain information, fallible individuals, and at the same time lifes on the line. There is science in what we do, yes, but also habit, intuition, and sometimes plain old guessing.

[p.253] Disaster occurs, and we call that a tragedy. But if someone writes it down, we call it science.

Beyond Fear:

Bruce Schneier güvenlik sistemlerinin nasıl tasarlanması gerektiğini, bugünkü sistemlerin çoğunun göz boyamanın ötesine geçmediğini anlatıyor. Terörizmin günlük hayatın parçası olduğu zamanımızda sağlıklı akıl yürütebilmek için böyle aklı selim ile yazılmış kitaplar önemli.
[p.8] When it comes to security, fear is the barrier between ignorance and understanding. To get beyond fear, you have to start thinking intelligently about the trade-offs you make.

[p.9] Ignoring reality is not an effective way to get healthier, or smarter, or safer, even though it might temporarily make you feel better.

Chances Are:
İstatistik ve olasılık kuramlarının ne kadar önemli olduğunu, temel olasılık bilmeden yapılabilecek düşünce hatalarını akıcı bir dille anlatıyor.
[p.3] Questions like "How do you know that?" and "What if it's not like that?" pose real problems - problems that have kept philosophy hard at work for over two thousand years.

[p.7] Every new observation brings with it a freight of information: some of it contains the vital fact we need for drawing conclusions, but some is plain error. How do we distinguish the two? By getting a sense of likely variation.

Guns, Germs, and Steel:
Tüfek, Mikrop ve Çelik adıyla Türkçe'ye çevrilmiş olan önemli bir eser, çok satanlar listesinden hiç inmeyecek gibi. İnsanlık tarihinde neden bazı medeniyetler serpilirken çoğu yokoldu? Coğrafyanın, ikliminin etkisi nedir? Zor sorulara akllı cevap önerileri getiriyor. Documentary video.
[p.25] We're assured that the seemingly transparent biological explanations for the world's inequalities as of A.D. 1500 is wrong, but we're not told what the correct explanation is. Until we have some convincing, detailed, agreed-upon explanation for the broad pattern of history, most people will continue to suspect that the racist biological explanation is correct after all. That seems to me the strongest argument for writing this book.

Collapse:

Guns Germs and Steel'in yazarı bu sefer odak noktasına yok olup giden medeniyetleri koymuş, günümüzdeki duruma ışık tutmaya çalışmış (durum parlak değil). Beni özellikle Easter adası ve Grönland hikayeleri etkiledi.
[p.38] Only when the public pressures its politicians will the companies behave differently: otherwise, the companies would be operating as charities and would be violating their responsibility to their shareholders.

[p.240] ...the Greenlanders found themselves in a very difficult environment. While they succeeded in developing an economy that let them survive there for many generations, they found that variations on that economy were much more likely to prove disastrous than advantageous. That was good reason to be conservative.

Saturday, November 04, 2006

Schneier on Security

Airline Security a Waste of Cash:
Exactly two things have made airline travel safer since 9/11: reinforcement of cockpit doors, and passengers who now know that they may have to fight back. Everything else -- Secure Flight and Trusted Traveler included -- is security theater.
Schneier on Security: Perceived Risk vs. Actual Risk:
When people voluntarily take a risk, they tend to underestimate it. When they have no choice but to take the risk, they tend to overestimate it. Terrorists are scary because they attack arbitrarily, and from nowhere. Commercial airplanes are perceived as riskier than automobiles, because the controls are in someone else’s hands -- even though they’re much safer per passenger mile.

Saturday, September 16, 2006

What is a Hacker?

Schneier on Security: What is a Hacker?: "A hacker is someone who thinks outside the box. It's someone who discards conventional wisdom, and does something else instead. It's someone who looks at the edge and wonders what's beyond. It's someone who sees a set of rules and wonders what happens if you don't follow them. A hacker is someone who experiments with the limitations of systems for intellectual curiosity."