Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

2/1/2007
07:35 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Schneier: In Touch With Security's Sensitive Side

Security icon's latest work explores the psychology, brain chemistry of security

Cryptologist and now, psychologist: Renowned security expert Bruce Schneier once again is turning security on its head -- literally. Schneier will share his latest research and insight at the RSA conference next week on the interplay between psychology and security. (See Schneier On Schneier.)

Schneier says the goal of his talk at RSA is not to discuss security technologies or tactics, but to explain how people think, and feel, about security. "A lot of the time at RSA, we are just puzzled why people don't secure their computers, and why they behave irrationally. Psychology has a way of explaining this," he says. "If we in the [security] industry expect to build products, we need to understand our customers."

The focus of Schneier's latest research -- which he says could culminate in his next book -- is brain heuristics and perceptions of security. He says security is both a reality and a feeling, with reality based on probability and risk, and feeling based on your psychological reaction to risk and "countermeasures" to security threats.

Often, our perception of risk doesn't match reality, and neuroscience can help explain this, he says. Perception of risk is often seared into our brains. Schneier says people are typically more afraid of flying than driving, for instance, even though statistically it's safer to take the plane. The brain's two systems of assessing risk -- the amygdala (in charge of processing senses like anger, avoidance, fear), and the neocortex, which gives us analytical processing -- don't really work in concert when it comes to perception versus reality of security.

Trouble is, it's difficult for the netocortex to "contradict" the amygdala, he says. The neocortex is a "newer" part of the brain that is still evolving, he notes. And the neocortex is the part of the brain that makes decisions on security "tradeoffs," he says. So sometimes, we make security decisions based more on emotion or perceptions than logic.

"Security is both a reality and a feeling," Schneier writes in a paper he'll be making public soon. And you can be secure even if you don't feel that way, or you can feel secure even if you're not, he notes.

Not many (if any) security experts weigh psychology into the equation, but then again, Schneier is not just any security guru. His work started as a cryptographer and has since evolved into an expert on everything physical security, including airport and school security. Schneier is also the the bestselling author of Applied Cryptography (as well as other books) and BT Counterpane's top security guy.

Schneier says the trouble with vendors missing the psychological component in security is that their products then fail. "The RSA show floor is filled with products that nobody uses. They don't install, they configure badly, or they don't actually work," he says. The user/human interface aspect of a product is more important than the technology, he says.

"Our problem as technologists is we can't pretend people don't exist. We must build security for people," he says.

He admits the human interface aspect of security products has improved. But security doesn't have the best track record in getting in touch with the person behind the user: email encryption, for example, didn't take off. "Over the years, no one used encryption" in email, he says. "It had nothing to do with the technology," but instead the ease of use, he says.

So how do you get into security customers' heads? Schneier says it's really not that hard. "The ways that they think about security decisions is actually very rational and predictable if you understand" the underlying brain heuristics and psychology, he says. "It's not 'look how dumb people are' but 'look how clever the brain is,' " he says. Getting a handle on brain heuristics can also help understand how attackers take advantage of them, too, he says.

The flip side of this: How can security customers make sure they don't make bad security decisions that are based on incorrect perceptions?

Schneier says he doesn't know if you can change brain chemistry for this. "My belief is that making you aware of it goes a long way," he says. "If you can understand you are just reacting from fear, you have a better shot at…understanding these human biases. Hopefully you can short-circuit them and improve on them and make it so we are not slaves to this," he says. "Fear is brain chemistry, but so is reason. We have to figure out how reason can trump fear."

If anyone can solve that puzzle, it's Schneier.

— Kelly Jackson Higgins, Senior Editor, Dark Reading

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/3/2020
Pen Testers Who Got Arrested Doing Their Jobs Tell All
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/5/2020
New 'Nanodegree' Program Provides Hands-On Cybersecurity Training
Nicole Ferraro, Contributing Writer,  8/3/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15058
PUBLISHED: 2020-08-07
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.
CVE-2020-15059
PUBLISHED: 2020-08-07
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.
CVE-2020-15060
PUBLISHED: 2020-08-07
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to conduct persistent XSS attacks by leveraging administrative privileges to set a crafted server name.
CVE-2020-15061
PUBLISHED: 2020-08-07
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to denial-of-service the device via long input values.
CVE-2020-15062
PUBLISHED: 2020-08-07
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.