(ISC)² Twitter Updates

  • (ISC)² Twitter Updates

    About the
    (ISC)² Blog

    • (ISC)² believes in the importance of open dialogue and collaboration, between both (ISC)², its certified members and members of business and society.

      (ISC)² established this blog to provide a voice to its certified members, who have significant knowledge and valuable insights to share that can benefit the information security industry, the people in it and the public at large.

      The postings on this site are the author's own and don't necessarily represent
      (ISC)²'s positions, strategies or opinions. (ISC)² does not control, monitor, or endorse any links provided in this blog and makes no warranty or statement regarding the content on any linked website.

      Those who post comments to blogs should ensure their comments are focused on the topic at hand. (ISC)² reserves the right to remove any post or comment from this site.

      Should you find objectionable content in this blog, please notify us as soon as possible at blog@isc2.org.

      Please click here for FAQs.

      Please click here for the Blog guidelines.

    « The Anti-Phishing Working Group: Counter eCrime Operations Summit | Main | Demystifying the Risk Management Framework »

    29 March 2010

    TrackBack

    TrackBack URL for this entry:
    http://www.typepad.com/services/trackback/6a00e54f109b67883401310ff5da0f970c

    Listed below are links to weblogs that reference Why people are not concerned about security on Internet Social tools?:

    Comments

    The more pressing concern is why people happily share their "secret information" that they use to retrieve passwords etc from other sites. It wasn't long ago that VP candidate Sarah Palin's Yahoo account was victim to that exact SNAFU.

    From my perspective, the main problem is that, as a communication medium, the Internet is very new (barely 20 years since Al Gore invented it ;-)) and Social Networking sites are even newer.
    The standard community rules that one uses when face-to-face work differently on the Internet.
    In the "Real World" we generally share information carefully with various groups of people we know: Family; Spouse; Children; friends; co-workers; government; strangers; what you did on holiday/stag-night - each gets different trust levels applied to them. The majority of these groups we meet face to face, or know where they're based.
    Most of us access the Internet from the privacy of our own homes/own iPhone, or at least, in an individual capacity. Unless you are involved in Pair-Programing, the chance of it becoming a communal activity are limited.
    As such, when people are alone, they behave somewhat differently compared to when they are face to face with people. I have no metrics, but I'm sure this plays it's part on what people do and share on the Internet.

    When we're on the Internet, the realization that potentially, the WHOLE WORLD has access to what one is writing doesn't cross anyone's mind as they sit alone at their desks.

    Google indexes everything, caches everything and that leaves even less room for secrets. By aggregating search data, it is even possible to connect posts made under pseudonyms, aliases or anonymous. In search, many of your statements are taken out of their original forums and out of context, too. What may be deemed perfectly acceptable on a specific forum could be deemed completely inappropriate when found in a global search done by a prospective employer!

    Few websites grant the content creators the appropriate amount of control on their data: the ability to limit viewing; the ability to stop Google's index; the ability to delete permanently... and even if there was, how many users would use it?

    I'm sure that many of us have at some point in time, shared something on the Internet that we wish we hadn't, or something that if taken out of context could be embarrassing for us.

    I honestly don't know the answer to this. Most people are too busy having fun on the internet to be concerned with these details of security and privacy. So though we can recommend to the users that they share data carefully, I don't how we'll convince most people to change their behaviours.

    I avoid making assumptions like this author does as far as the motivations and 'thoughts' that other people have. Same goes for the other comment on the article.

    In particular, what is troubling is security professionals such as these that try to take the opportunity to make more of a social statement rather than address a valid security issue with any sense of utility.

    Hi Paul,

    I'm not trying to make a "social statement" but understand a social problem and find a way to address it.

    What's your alternative? Close my eyes and pretend that the problem doesn't exist?

    Regards

    An alternative would be more in terms of your sociological and behavioral comparative to say the field of psychology that deals with many forms of pathology and address it there.

    Instead of preventing, since this is not really possible, they treat the condition. So as a security professional may be you can provide services to help, assist, and educate. We all are vulnerable to a security compromise. Some more than others such as those who take more risks therefore an increased likelihood is the result but does not guarantee an event will happen.

    You state "What can we (Security Professionals) do about it?" You gave some good examples. I have no problem there, but your earlier statements do little to explain or support the situation.

    But sometimes as a security professional you should discriminate that not everything needs you to take an action.

    The comments to this entry are closed.

    Recent Contributors

    Past Contributors