Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Careers & People

Stop Blaming Users. Make Security User-Friendly.

50%
50%

Jelle Niemantsverdriet of Deloitte visits the Dark Reading News Desk at Black Hat to explain how security can be improved if security tools, error messages, and help desk calls educate users and 'put a smile on someone's face.'

Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
bboink1
100%
0%
bboink1,
User Rank: Strategist
9/15/2016 | 10:09:50 AM
Users Still need the Blame
Users are the weakest link.  When the security measures are in place and the user still does the wrong thing because there are no consequences adapting the security to them is a futile effort.  The only fix to that is to hold the users accountable.  Case in point, trying to make cars that keep you in your lane or stop for you is needed because people are not paying attention.  How about when they cause an accident due to texting and driving they get rewarded with license revocation.

As far as taking the empathy approach with the user, it is difficult to build security around the "I am going to do what I am going to do regardless of what I am supposed to do" attitude. No matter how friendly you make the security if it inhibits the user from doing what they want they will ignore and find a way around.

Designing better error messages for the users is a good idea.  It is possible if the error message was informative it would help the tech that has to work on it.  .That being said most of the users do not read the error message so that would not help a user.  Just as they do not read the popup that downloads the cropto-ware on their system.  An example of this is when the help desk gets the call of "It just stopped working," and "I didn't do anything."  Of course the answer of "ummm....I don't know" when asked "What did the error message say?"  Users just click without reading.

The point of rewarding them for doing what they are supposed to do is like giving them a trophy for showing up.  Then they will expect a trophy all of the time and the value of the "incentive" will diminish.  This is what created the situation that we are in with the users not caring now.

I do agree that security must be made to be a bit more user friendly.  I also believe that the users will adapt in a downward direction to put us back in the same situation.  I think accountability is the direction that will produce a bigger bang for the buck.
Why Cyber-Risk Is a C-Suite Issue
Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
DevSecOps: The Answer to the Cloud Security Skills Gap
Lamont Orange, Chief Information Security Officer at Netskope,  11/15/2019
Attackers' Costs Increasing as Businesses Focus on Security
Robert Lemos, Contributing Writer,  11/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-19071
PUBLISHED: 2019-11-18
A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_91x_mgmt.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering rsi_prepare_beacon() failures, aka CID-d563131ef23c.
CVE-2019-19072
PUBLISHED: 2019-11-18
A memory leak in the predicate_parse() function in kernel/trace/trace_events_filter.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-96c5c6e6a5b6.
CVE-2019-19073
PUBLISHED: 2019-11-18
Memory leaks in drivers/net/wireless/ath/ath9k/htc_hst.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering wait_for_completion_timeout() failures. This affects the htc_config_pipe_credits() function, the htc_setup_complete() function, ...
CVE-2019-19074
PUBLISHED: 2019-11-18
A memory leak in the ath9k_wmi_cmd() function in drivers/net/wireless/ath/ath9k/wmi.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-728c1e2a05e4.
CVE-2019-19075
PUBLISHED: 2019-11-18
A memory leak in the ca8210_probe() function in drivers/net/ieee802154/ca8210.c in the Linux kernel before 5.3.8 allows attackers to cause a denial of service (memory consumption) by triggering ca8210_get_platform_data() failures, aka CID-6402939ec86e.