About RSS
Search for: in 
Schneier pic
R E L A T E D   C O N T E N T
Jargon Buster

ADVERTISEMENT

Users fear venturing too far online

Experts warn more must be done to safeguard internet retail and banking

Phil Muncaster, IT Week 20 Oct 2006
ADVERTISEMENT

At the annual Information Security Solutions Europe (ISSE) event in Rome this month, some experts warned that the growth of e-commerce and online banking is being undermined by a lack of awareness and fear of transacting via the internet.

In a panel debate, Peter Keller of telecoms firm Swisscom argued that as many as a third of consumers may be limiting themselves to browsing and email because they are afraid to attempt more complex procedures online.

He blamed scaremongering by the mass media and poorly engineered, difficult-to-use products as the main causes of user insecurity.

Security expert Bruce Schneier agreed, arguing that internet service providers (ISPs) could play a vital role in providing support and protection for consumers.

"Computers are too hard to use," he said. "Home users don't have an [IT department] to be their trusted security adviser, but ISPs could fulfil that role."

He added that vendors should be held liable for flaws in products and services that can result in enterprise customers suffering financial loss, bad publicity or non-compliance with regulations.

"If you don't [enforce vendor liability] the problem will never be fixed, but if you do, the technologies will come out of the woodwork to fix the problem because there will be money to be made from it," Schneier argued.

Keller said vendors must inform customers about the "true risks rather than confusing them with too many security messages". He added that regulation may be required to enforce quality and reliability of some products.

Michael Howard, a senior Microsoft security manager, admitted that Microsoft has been guilty of bombarding users with overly technical information.

"Users don't make good trust decisions partly because they don't know what's going on," he said. "No one would understand some of the dialogue boxes we've given."
He added that technology vendors cannot assume the end-user is educated, so security measures should be built in as standard.

"We're going to provide these baseline defences in the operating system to protect you and then provide the functionality to unlock things if you are an alpha geek and want to do this," he said.

The Italian minister of communications Paolo Gentiloni urged the European Commission to regulate in matters of "standardisation, interoperability and security certification" to create a minimum standard for security. "It would be worth achieving a common position within the European Community," he said.

Gentiloni also warned that IP-based applications such as IP TV and VoIP need "new standards and models in order to guarantee communication security".

The European Commissioner for Information Society and Media, Viviane Reding, acknowledged in her keynote the importance of diversity in IT to reduce the risks of depending on one type of technology. The Commission "expects the private sector to be proactive in areas [such as] usability and interoperability ", she added.


Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Randstad Technologies
Project Manager required to join fast-growing IT software house in the Bristol area. We are looking for candidates with strong Project Management skills looking to better their skills with a market-leader offering long-term progression. The ... more >
| Computer People
My client is looking for an ETL Developer to identify, prioritise and develop new ETL packages and maintaining existing packages. Delivering, maintaining and testing ETL solutions. Investigating new technology platforms and technologies. Documentation of ETL ... more >
| Computer People
Computer People are currently recruiting for a large and rapidly expanding IT Services company that are looking to add to it’s talented ITIL Change Management function within their Central Service Center based in Milton Keynes. ... more >
| Computer People
Web amp; SQL, Crystal Reports, .NET (C# amp; reputation in the Market. They seek a creative Developer with PHP experience to join their team. We are looking for someone who has a strong understanding of ... more >
More job opportunities