3 ms·
Which pieces by Schneier were not well-informed, or in which ones was he talking about something outside of his domain?
by febeling 14y ago
Which pieces by Schneier were not well-informed, or in which ones was he talking about something outside of his domain?
- iuguy 14y agoIt's surprisingly common. Here's[1] the most recent example of Schneier talking out of his domain with the potential to cause damage. The problem is that Schneier is a pundit, not a security expert. He has a good knowledge of cryptography but as a media pundit he's often asked questions outside of his domain and on responding or commenting he's referred to in the media as an expert. This is precisely what happened with his views on Airport Security. He was expressing views as an expert when he was known for cryptography and had no domain experience in airport security. Over time he's clearly researched it and had more interest in it, but his earlier stuff shows his lack of domain knowledge, yet because of his media presence he's automatically deemed an expert, and this is dangerous. In the most recent example of security awareness training, I would bet £5 (to be donated to the Open Rights Group, the UK equivalent of the EFF) versus the equivalent in dollars to be donated to the EFF that Schneier never once in his lifetime has been involved in implementing a security awareness training programme. Yet his commentary on this marks him as an expert in the field as far as the media is concerned, and such views coming from 'an expert' may impact the security awareness programmes of many people trying to improve security in their own organisations worldwide. There's strong and well put opposition to this from Dave Kennedy[2] and Andy Ellis[3], the latter of which is Akamai's CSO, and someone who actually practices security on a day to day basis. Just to be clear, I am generally critical of Schneier and I think it would be unfair not to state this. While I'm not a cryptography expert I recognise the work he's done in that field, however where his points have crossed over into my domain knowledge I've found his comments often show a lack of experience for someone deemed an expert by default. I don't blame him for this, but I do believe that he benefits from it and does nothing to counter the impression (that he is an expert in areas he clearly isn't). [1] - http://www.schneier.com/essay-419.html http://www.schneier.com/essay-419.html [2] - https://www.trustedsec.com/march-2013/the-debate-on-security-education-and-awareness/ https://www.trustedsec.com/march-2013/the-debate-on-security... [3] - http://www.csoandy.com/files/why_bother_with_awareness.html http://www.csoandy.com/files/why_bother_with_awareness.html
- febeling 14y agoI don't find it very surprising that providers of security awareness programs don't agree with Schneier's arguments against their offering. But since they have a strong financial incentive to disagree with him I'm doubtful about their arguments. Their arguments were also not convincing to me. Let me quote a random and very shallow bit from the first linked post: "An education and awareness PROGRAM is not a one hour CBT and clicking through something. It’s education and awareness just like your HR department helps you navigate to your expenses." That sounds desperate.
- iuguy 14y ago> I don't find it very surprising that providers of security awareness programs don't agree with Schneier's arguments against their offering. Erm... I wasn't talking about commercial providers of security awareness programmes. I'm talking about people who work in security who actually implement security awareness programmes as part of their security management processes, and the risk of a higher up being convinced that it's not worthwhile because schneier said so. I've actually had a phone call this morning with one of my clients where this article was raised as justification for cutting the security budget next year by reducing spend on security awareness. This is for a major european defence manufacturer who's under pretty much constant attack by people looking to steal their IP. In reference to your quote, that's not desperate, it's fact. A proper security awareness programme is created and maintained by the organisation itself on the basis of trying to find the best way to counter the threats the organisation faces. Some organisations will find that the need for this is relatively low and that the biggest threats they face are things like password sharing and internal things with disgruntled employees. Others may find that they're under constant attack from external threat actors and need to train people to help support their detection capability. In either situation it's definitely not a one hour CBT, it's more complex, it's more nuanced and it's ongoing.