Ending the epidemic of ignorance

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

COMMENT

Because of my experience, groups frequently ask me to be a guest speaker about security issues. In most cases, however, the majority of the audience is already painfully aware of the immense challenges presented by Internet and information security.

That means that many of my presentations amount to nothing more than "preaching to the choir" about current security issues. And while I enjoy participating, reminding people to click the Windows Update menu item in Internet Explorer each week isn't even a mildly interesting topic for most IT professionals, and neither is my suggestion to use free antivirus software.

I've said it before, and I'll say it again: The horrible state of Internet security is due to an epidemic of ignorance. But companies can't just sit back and accept this lack of knowledge. Let's look at some simple steps your organisation can take to dispel this ignorance.

Ignorance is not bliss
One of the most prevalent problems with security is that most users are completely unaware of the risks of insecurity. And this problem will not fix itself.

It's a simple fact that most people who use a computer have little understanding of — nor are they interested in learning — the details of how their computer works. In fact, I would argue that the only times most people become interested about the operation of their computer system is when it stops working.

Developing end-user education opportunities in the corporate environment — and encouraging employees to attend them — is one way for companies to diminish computer illiteracy. Providing incentives for attending classes and for keeping a computer updated and virus-free are additional options to consider.

Helping those who help themselves
Those of us who are computer-savvy enough to install and update antivirus software and click Windows Update each week aren't doing enough to help ourselves. Even if they're not in an official support position, I bet the majority of readers have found themselves helping co-workers, family, and friends fix something on their computer or helping them recover from a virus or worm.

The old saying about teaching a man to fish has never been more valid. Helping one person and telling him or her to pass along the knowledge you shared does more in the long run to improve Internet security overall.

Consider setting up an informal mentoring program to encourage more computer-savvy employees to share their knowledge with their coworkers. Setting up a bulletin board for posting tips and hosting a lunchtime training session about security are also low-maintenance ways your organisation can promote security awareness.

Focus on your users
We are all aware of the current security problems wreaking havoc. However, while IT pros often enjoy discussing the various security challenges, these conversations do nothing to educate the average user.

The average user uses Microsoft Windows, and Windows is where the battle against insecurity and ignorance needs to start. The sheer extent of the threat to the Internet from insecure computer systems using Windows justifies taking the time to educate as many people as possible about how to secure their systems.

Jonathan Yarden is the senior UNIX system administrator, network security manager, and senior software architect for a regional ISP.

Talkback

I couldn't disagree more with the opening sentence here. While the end user IS responsible for a certain amount of knowledge required to implement proper security, the fact is that the root of the issue is systems that are insecure by design, i.e. Windows.

Between the tight coupling of the OS and many applications like IE, Outlook, and Office, and the idea that running as the super user is fine and dandy, Microsoft's Windows has done more to harm the internet than all other Operating systems combined.

In earlier versions of the MCSE course, they actually suggested it was safer to add certain users to the admin group rather than to either create separate accounts for them or give them the administrator password. I knew after reading that one sentence the MCSE program was a joke, and the people who wrote it clueless about real security.

If all systems were designed to be secure from the ground up, as are unix based systems and dedicated OSes like OS/400, MVS, and VMS, the burden on the user would be much reduced, and the number of compromised systems on the internet would be a small fraction of what it is today.

via Facebook 24 May, 2005 15:16
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

2 hours ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

10 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

11 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

12 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

14 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

15 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

17 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

17 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

17 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

18 hours ago by via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

20 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

1 day ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

1 day ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

1 day ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

1 day ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

1 day ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint