Welcome Guest. | Log In| Register | Membership Benefits
Dark Reading's hacked-off Weblog

Topics:   Hacked Off
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

Intel Buys McAfee: Is The PC Security Model Dead?

When it comes to emerging platforms like smartphones, tablets, and embedded networked systems, the old model of separate antivirus security companies is officially dead. And Intel's purchase of McAfee puts a stake in it.

Aug 20, 2010 | 02:31 PM | 

By Rob Enderle
Dark Reading
When it comes to emerging platforms like smartphones, tablets, and embedded networked systems, the old model of separate antivirus security companies is officially dead. And Intel's purchase of McAfee puts a stake in it.The PC model simply wasn't sustainable because it put security companies at odds with the platform providers they secured, and the solutions were an ugly trade-off of solving some potential security exposures by causing consistent performance problems. Intel's move to buy McAfee, much like Microsoft's purchase of Sybari years ago, is an indicator of change that will felt as the next generation of technology is developed for the market.

The reason Microsoft decided to let third parties do security on Windows was that, initially, its entire model was based on a heavy third-party application plan. In addition, security initially was mostly about access, and given that computers generally weren't networked, viruses that spread via floppy drives were relatively easy to manage. So Microsoft left it up to others, and an industry of the likes of McAfee, Symantec, and Trend Micro was born.

But so was a big problem. You can't sell security to a secure customer: You have to make them feel insecure. This is called the insurance sale; you have to make people think they are going to have a loss if you want them to buy something that will compensate them for it. If folks feel safe, then they won't buy.

This put security vendors, particularly AV vendors on Windows, at odds with Microsoft because they increasingly had to find and point out flaws in Windows in order to sell products that mitigated these flaws.

The process to both intercept and scan for viruses remains resource-intensive. Until there was performance headroom in the past decade, a virus scan could bring a PC to its knees; users either turned the process off or complained about the poor performance. This became particularly painful as Apple improved and users had a choice, and increasingly chose, the platform that didn't have antivirus software.

Smartphone, tablet, and embedded vendors certainly don't want to repeat this mistake, and Intel is offering them an alternative by buying McAfee.

This won't happen overnight, nor will it be easy, but Intel's plan is to recognize that security exposures are not only going to get worse, but they also will spread to other systems that are increasingly being connected. Monitoring, communications, automotive, medical, manufacturing, in-flight, and law enforcement systems (and this is hardly an exhaustive list) are being connected to the network, and that connection becomes vulnerable to attack by viruses and hackers. However, the companies building and selling these systems generally have no competence with this kind of problem because their systems have either not been connected, or they used dedicated and secured networks and not the Internet.

This could lead to unimagined exposures that either could significantly slow products to market or cause them to fail spectacularly once they arrive. Even the new smartphone and emerging smartphone-based tablet space -- which is designed to be networked -- is largely driven by vendors that haven't really had to worry about viruses and hackers except when it comes to breaking the carrier lock on the devices. Even for that relatively simple exposure, they have had a troubled history.

This suggests a different approach: one in which security is designed in at the front-end of a product. Intel now has a plan for those vendors that don't have the expertise to do this.

Intel's purchase of McAfee makes sense because you need a team that has expertse in the threat in order to deal with it in a timely way; the PC market is where the expertise exists. Symantec was too broad and expensive, firms like Kaspersky too limited and likely too remote physically, and McAfee appeared to be a bargain. So a marriage was conceived.

Because Intel doesn't yet have a software competence, it is at least initially leaving the firm separate, but I expect it will eventually revisit this as it discovers the need to combine the companies' acquired software competencies into a more cohesive unit. The goal, however, is to create an environment in which security is designed in from the start, with hardware tuned for it and performance impact, minimized.

This path is not without risk: Intel is neither a software nor security expert at this point, and acquisitions often challenge firms as they learn to understand them. However, without an edge, Intel likely wouldn't be able to make much inroads into the targeted markets, and performance alone isn't enough edge. Security in an insecure world could be just the edge to get it into consideration and to design wins once the solution is fully fleshed out.

That makes this one of the few high-risk strategic decisions this year -- and large stable companies like Intel aren't typically known for that. That's why large, stable companies often don't stay large and stable. More of them should take regular bets to better assure their long-term future. Intel did, and suddenly it isn't just big -- it's also interesting again.

-- Rob Enderle is president and founder of Enderle Group. Special to Dark Reading.



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS









  1. Cookies, Social Media And FireSheep
  2. SMB Guide To Credit Card Regulations, Part 2: The Low-Hanging Fruit
  3. HP And The Scary Corporate Fifth Column Concept
  4. Taking USB Attacks To The Next Level
  5. NoSQL: Not Much, Anyway
  1. Taking Cybersecurity Lessons To The Bank
  2. Researchers See Real-Time Phishing Jump
  3. 'BlackSheep' Sniffs Out Firesheep WiFi-Hacking
  4. Slideshow: Ten Free Security Monitoring Tools
  5. A Different Spin On Sleuthing Stuxnet
  6. M&A Activity Muddles Database Security
  1. Secure Managed Web Hosting Saves 960.gs from Malicious Hackers
  2. Access Governance as a Business Service: An Integrated Strategy for Automation with ITSM
  3. Business Driven Access Management and Governance: Simplifying the Delivery and Governance of Access Throughout
 
 


 
  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag
 
  February 2012
January 2012
December 2011
November 2011
October 2011
September 2011
August 2011
July 2011
June 2011
May 2011
April 2011
March 2011
February 2011
January 2011
December 2010
November 2010
October 2010
September 2010
August 2010
July 2010
June 2010
  May 2010
April 2010
March 2010
February 2010
January 2010
December 2009
November 2009
October 2009
September 2009
August 2009
July 2009
June 2009
May 2009
April 2009
March 2009
February 2009
January 2009
December 2008
November 2008
October 2008
September 2008