Find Articles

iTSHOWCASE News

Sign up for a newsletter

While the world digitally develops, are we actually built for technology?

Thursday, 14 January 2010

In the light of the announcement that Google operations are pulling out of China, Jay Abbott, Threat and Vulnerability Management, PricewaterhouseCoopers LLP, comments on the security issues prevalent in this case

"In such cases as Google in China, the attackers target the users themselves - typically the weakest link in the systems security chain.

"Phishing is a common way of attacking a large volume of users on the internet and simply makes use of the fundamental need to trust. This need or desire to trust, common in our nature, means that a well worded, seemingly legitimate email will most likely be actioned in the intended way. Leading the phishing victim to a specific site designed to seek out valid authentication details.

"In more technical attacks, the site would exploit a common weakness within the computer system to implant malicious programs designed to capture keystrokes or spy on the screen. In either case, the resultant data is simply harvested into a database and then exploited at will by the individuals behind it.

"However, a more common form of attack is to simply guess the password of the individuals in question. Again, the concept of remembering a complex password is opposed to our own nature, and as such, is more likely to result in an associate password being used. This of course leaves the users thinking they are secure by virtue of having a password, but in reality it serves no purpose. Contextually, many passwords are easy to guess in a motivated attack.

"A recent survey highlighted the most common password in use on a free major web based email platform was in fact "123456."

All of these points lead us to the question, is a simple password enough security for any type of system or data, even free web mail? And are we in fact programmed to simplify security to the point of attack? While we build technology are we actually built for it?

Tell us your news:

If you have industry related software news that you would like to have published, please use this submission service to have your news considered for publication

Tell us