18 June, 2012

Computer security and that pesky "human vulnerabilities" factor

The latest issue of CACM published a blog post by Jason Hong entitled "Protecting Against Data Breaches" that caught my eye. Jason attempted to offer some simple guidelines ("a three-pronged approach") to combat ongoing issues in computer security. While I agree with Jason that computer security breaches are a major issue given the increasing amount of personal data about regular people that has proliferated online, I think that the suggestions he provides while useful are perhaps not radical enough. Oh, they are sound enough from a technological point of view and Jason carefully notes the importance of the "human vulnerabilities" implicated in many of the recent big hacks - which is something that has been willfully ignored by the security software developers and researchers. However, I would argue that this "three-pronged approach" simply reinforces the current paradigms and here is why:

Part 1: Get research and industry to develop new best practices, create better tools and have better taining of software developers. It is not clear what Jason means by new best practices, but perhaps addressing the issues of building in separate data architectures and developing new ways of convincing users to "do the right thing" by changing their passwords often, not re-using passwords, getting better at detecting phishing attacks. This is something that is already done quite a bit - who hasn't encountered annoying corporate policies requiring you to change your password every 3 months? Yes we can get better at what is already getting done, but there is little evidence that better will work where the current approaches clearly really do not. 

Part 2: Complement these technical approaches with a stronger legal structure that can properly incentivize computer companies to take stronger measures protecting customer data. This one is interesting as it puts the onus on policy and governmental action rather than using technological solutions to the problem. I am reading this as - make personal data loss MORE illegal and put the companies whose data is stolen under the gun. While this might be useful to encourage Sony to do more about security to avoid major losses such as the Playstation debaucle, this also might point to a little problem. Given the ongoing arms-race between the hackers and security sector, at what point is the defence of "industry standard" not going to be enough? And if it is not, how then might this work? Given the rather uneasy relationship between computer scientists and policy makers (i.e. computer scientsts sometimes act like ostriches with heads in the sand when it comes to potentially influencing policy or questioning the ethical implications of their own research) I am not seeing an easy way forward with this one, especially in the rather pro-business and less-regulatory climate in the US. Of course, the consumer block can wield quite a bit of political power in the election season but once again, I am not sure this is enough or even possible. 

Part 3: Develop new ways of actually addressing the human vulnerabilities, in the form of simpler and better-designed user interfaces, more research to gain a deeper understanding of human biases and social influences in decision-making, and better ways of motivating and training people so they are effective in the face of these ongoing attacks.  This one is where things get really tricky. On the one hand, this isn't all that different from Part 1, except software developers got substituted by people with the addition of - we need to figure out how to change people's behavior more effectively to fit the needs of the security protocols.

This last point is perhaps the most important and the reason why I think the whole discussion mainly reinforces the ongoing and largely flawed paradigm of current computer security practices. Jason laments the common software developer view of users as "stupid" but I would argue that in fact that is a very correct view. Except it doesn't often encompass the software developers themselves and it should. All users are stupid - me, you, them... While we might be smart in some of the things we do likely there are many ways in which we also tend to be very stupid. Password reuse, for example is a rampant practice. I do not know anyone who does not reuse their passwords, including myself, and I am acquainted with quite a lot of computer professionals and all of us should know better. The thing is, either all of us and everyone else in the world are stupid, or the expectations for proper computer security practices are simply impossible to sustain.

I would argue that the current computer security designs make certain assumptions about the type of person that will be using the technology. Oddly enough, their perfect user would be a clinically paranoid individual with infallible memory. You would have to have a perfect memory to never reuse passwords for example. Imagine how many unique passwords you would have to remember given the amount of online services we use? Even with password reuse I can't remember the right combination of letters and numbers half the time. How paranoid do you have to be to methodically change all of your passwords every three months? That's like changing the locks on your front door once a year and that's a very unusual practice. Somehow I don't think there are many such people in the world, but perhaps they are more common in the computer security profession?

What I am hearing Jason say is that in computer security human vulnerabilities are most often the weak link and this is the weak link that is mostly ignored as we develop more and better technical solutions to the problem. This is an important point to make and he points to the need to engage policy and the social aspects of the issue. Yet the solution proposed here is little more than: we must find better ways to change people to fit the needs of security protocols. Changing people to fit the needs of technology (changing policy to fit technology, changing pratice to fit technology) is a common enough approach in the tech sector and it fails early and often. I wonder though, can we take people as a starting point and their failings of memory, the tendency to ignore apparent risks, the plain laziness - and redesign the dominant computer security paradigms to not only take into account but to take advantage of these? Perhaps this might result in systems that are far more successful than attempting to change ourselves to fit the current logic of computer security software and practices - changing outselves into clinically paranoid individuals with perfect memories seems an impossible task. 

No comments:

Post a Comment