Risk
2/29/2008
04:50 PM
Keith Ferrell
Keith Ferrell
Commentary
Connect Directly
RSS
E-Mail
50%
50%

F-Secure Survey Shows Misplaced Security Confidence

A new computer-use survey from security firm F-Secure shows that the majority of more than 1,000 respondents understands the importance of updating virus definitions. Yet less than 20 percent understood the need for frequent definition updates.

A new computer-use survey from security firm F-Secure shows that the majority of more than 1,000 respondents understands the importance of updating virus definitions. Yet less than 20 percent understood the need for frequent definition updates.The F-Secure Online Wellbeing Survey found that more than 90 percent of the North American and European respondents had security software installed on the computers.

But 76 percent of the participants felt confident that their anti-virusware would protect their computers from infection, while only 19 percent understood that virus definitions need to be checked/updated daily (at least.)

The disconnect reflects one of the largest security issues facing small and midsize businesses (and bigbiz, and consumers and everybody else, for that matter) -- the failure to understand the constant threat/constantly evolving threat environment in which we work, play and surf.

While F-Secure's purpose in underwriting the third-party survey is to help market its security services, as well as to offer a picture of the (over)confidence level of many computer users, the underlying message of ongoing computer-user naivet or outright ignorance, sometimes willfully so) should get equal attention from every one of us.

Until our colleagues and employees (and everyone else who calls on us for help because we "understand computers") come to understand, at the very least, for themselves that the Net, e-mail, downloads and all the rest of it is filled with very large threats that can change hourly, the confidence/safety gap is unlikely to narrow.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, September 16, 2014
Malicious software is morphing to be more targeted, stealthy, and destructive. Are you prepared to stop it?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0985
Published: 2014-09-20
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the NodeName parameter.

CVE-2014-0986
Published: 2014-09-20
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the GotoCmd parameter.

CVE-2014-0987
Published: 2014-09-20
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the NodeName2 parameter.

CVE-2014-0988
Published: 2014-09-20
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the AccessCode parameter.

CVE-2014-0989
Published: 2014-09-20
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the AccessCode2 parameter.

Best of the Web
Dark Reading Radio