If I had to pick what I thought were the most prevalent reasons for general lack of security – in an IT environment or a software environment – near the top of that list would be stress. Stress? What’s that got to do with security? Quite a lot. What happens when you get stressed, or worse, burnt out? You stop thinking straight. You start accepting things as they are just so that you can get through it, and get on with your life. You stop thinking about security. When you’re under pressure to make a system work, one of the last things you want is a security option getting in your way. If you can get it to work faster[…]

Nick’s post yesterday showed just how easy it can be to get a user to give up a password. For most homes (and probably many small businesses), you don’t even need to go that far. Many device manufacturers have decided to sacrifice security for ease of use, specifically being able to plug in a device and have it “just work”. The worst example of this that comes to mind is the wireless router. More often than is reasonable, you can connect to someone’s network without any authentication and have your way with the internal network. Or, maybe you just want to engage in some questionable activities on the Internet. Perhaps, you can hijack their DNS records to make mybigbank.com point[…]

Patrick Dempsey (former FBI agent) recently wrote on his blog that one of the ways to make the Internet safer for users might be to create a second Internet&.

The solution might be to establish two Internets — the current Internet and a new, more secure Internet where users would be required to register prior to gaining access.

Technical and practical considerations aside, it’s an idea that wouldn’t enhance security for anyone. A second Internet might in fact make thing even worse.

One of the irritating problems I have to deal with as a developer is the fact that I don’t really get to make any decisions. Sure I can make design decisions regarding the implementation of code modules, but when it comes to post-deployment issues, especially regarding security, all I can do is make some suggestions to managers and hope for the best. For example, in the extremely unlikely event that I find a security hole in one of my impeccably designed modules, I can write up a summary of the bug, mitigating factors, risks, and level of effort it would take to fix it. But, it’s not really up to me whether it winds up getting fixed or not. A[…]

Today on WTOP, I heard about Amtrak’s new security procedures – randomly screening bags. Now, supposedly, the randomness of these searches has been vetted through NY courts, because they’re using the same techniques. I, personally, take the train to NYC – for multiple reasons, the biggest being that I can practically get to NYC in about the time it takes to be at the airport waiting to go through security. I can also show up at the station literally as the train is leaving and get on it (yes, I’ve done it, no, I’d rather not repeat that adventure). One of the major “Excuses” given for the increased security is that terrorists have targeted other train service in other countries,[…]

It’s a shame that “national security” has turned into such a divisive political issue. Politicians have a way of managing to argue in the absence of facts, as facts just don’t get voters excited quite like rhetoric does. Congressmen give bills names like the PATRIOT Act and the Protect America Act to make opposition look treasonous without having to explain why.