There is a post at IT Conversations which is Alan Cox’s presentation from the 2005 European Open Source Convention entitled Computer Security – The Next 50 Years. It’s a 20 minute discussion available for listen or MP3 download, and Alan brings up some interesting points. I’ve transcribed his introduction below.

If we’re going to talk about security, we need to talk about the threat. What is the biggest threat out there? Well, as far as we can tell—I can tell at least—in the longer term, the nightmare security risk is the employee, or the person using the computer system. They’re really inconvenient things. You can’t formally verify people—it just doesn’t work. They operate inside of your security system, in most cases, so they can actually do their job. They work for you, and worse than that, they mean well. If they were malicious, you could get rid of them. If they mean well, they’re harder to deal with. So, a lot of security in the future has to be around stopping people who mean well, doing things they shouldn’t.

This was linked on Slashdot this morning and some good discussions followed.