Pseudo-Security

Pseudo-Security

Update: 2021-06-25
Share

Description

In this episode of Beneficial Intelligence, I discuss pseudo-security. The lock on your front door is not secure. It takes an experienced locksmith an average of 7.1 seconds to manually an average door lock, and it's even faster with a "pick gun." 

If locks are so bad, why don't we have even more burglaries? Because your total security does not only depend on the lock. A would-be burglar has to contend with the risk of somebody being home, neighbors noticing you, a camera on someone else's house recording you, and cops grabbing you and putting you in jail.

Like locks, passwords also do not protect you. At least one of your thousands of users has re-used the company password somewhere else. That means it will end up in one of the large hacker databases where identities can be bought for pennies. Then a hacker can sit comfortably in a basement in Moscow and run software to try thousands of username/password combinations with zero chance of being caught.

In the military, I learned that barbed wire that was not constantly observed was dangerous pseudo-security. You think you are protected, but when the enemy attacks, you will discover that your wire has long since been cut. 

Barbed wire cannot stand alone. Your door lock cannot stand alone. Your passwords cannot stand alone. You need to complement password security with two-factor authentication, IP address verification, time restrictions, network segmentation, anomaly detection, and all the other tools in the IT security toolbox. Passwords alone are pseudo-security.

 

Beneficial Intelligence is a weekly podcast with stories and pragmatic advice for CIOs, CTOs, and other IT leaders. To get in touch, please contact me at sten@vesterli.com

Comments 
In Channel
People Shortage

People Shortage

2021-11-2605:43

Data Hoarding

Data Hoarding

2021-10-2907:29

Monoculture

Monoculture

2021-10-1509:04

Trust, but Verify

Trust, but Verify

2021-10-0109:34

Time to Recover

Time to Recover

2021-09-1708:28

Goal Fixation

Goal Fixation

2021-09-0309:10

Narrow Focus

Narrow Focus

2021-08-2008:28

Back to the Office

Back to the Office

2021-08-0608:38

Humans and Computers

Humans and Computers

2021-07-2306:42

Competition

Competition

2021-07-0910:18

Pseudo-Security

Pseudo-Security

2021-06-2507:53

Good Enough

Good Enough

2021-06-1807:55

Unnecessary Roadblocks

Unnecessary Roadblocks

2021-06-0409:08

Expectation Management

Expectation Management

2021-05-2807:50

Gaming the Metrics

Gaming the Metrics

2021-05-0710:31

Accidental Publication

Accidental Publication

2021-04-3007:55

Irrational Optimism

Irrational Optimism

2021-04-2308:05

Risk Aversion

Risk Aversion

2021-04-1605:23

Biased Data

Biased Data

2021-04-0907:29

loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Pseudo-Security

Pseudo-Security

Sten Vesterli