Tuesday, January 21, 2003

Symptom-Driven Digital Security

Why digital security is like modern medicine -- symptom-driven?

If you bleed, patch it. If you have cancer, cut it out.

If you have a computer virus, install an anti-virus. If you are getting spam, get a spam filter.

Why are we so symptom-driven? (Because we want instant gratification?)

Often, we have to fix the problem when the symptoms occur -- or the symptoms might kill us. However, we need to ask the basic questions as to WHY cancer forms or WHY viruses can function.

If we get back to basics, we will start to realize that one of the root causes of computer insecurity is the lack of strong identity in our digital systems. (Another being software bugs.)

