USENIX LISA: Security Theater Plays a Role - Bruce Schneier's Keynote
The opening keynote Thursday of the USENIX LISA conference in San Diego was by author and security expert Bruce Schneier. In his opinion "perceived security" should be an aspect of all security implementation.
The large conference room was packed at Schneier's presentation, "Reconceptualizing Security." In one of his first slides, he pointed out that security has always been one of the basic human instincts by showing the part of the brain known as the amygdala where the emotion of fear (and its opposite, security) is seated. Schneier joked that "the newer part of the human brain responsible for heuristics is still in beta." He undermined the discrepancy between subjective feelings and provable facts with a few examples. Deviating from his slides and presentation material, he relied mainly on his words and gestures. "Security is at one time feeling and reality," according to his thesis, "You can feel safe without actually being safe, and you can feel unsafe for no apparent reason."
Schneier applied his thesis to a phenomenon he called "security theater." As an example he used the safety screw cap, designed to quell any fear that the content of the bottle might have been tampered with. He could think of at least ten ways that the content could be compromised, mentioning a syringe for one. Nevertheless, tamper-proof bottles provide an objective sense of security, which proved a saving grace for the medication industry after some well known poisoning incidents. Schneier felt that "as technicians, we kid ourselves that the security for which we're responsible is reliabable. That isn't true. We forget that humans play a major role."
Ignoring the emotional part of security is wrong in Schneier's judgment, and he advises technicians to incorporate the "security theater" concept in their work. Responding to a question about statistics, he suggested that they have little effect: "People who know statistics think they work better, but they don't." According to him, security models should adhere closely to reality, while recognizing that reality is mutable. His conclusion: "It's only when the feeling and the reality of security converge that we have real security."
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters
Support Our Work
Linux Magazine content is made possible with support from readers like you. Please consider contributing when you’ve found an article to be beneficial.
News
-
Rhino Linux Announces Latest "Quick Update"
If you prefer your Linux distribution to be of the rolling type, Rhino Linux delivers a beautiful and reliable experience.
-
Plasma Desktop Will Soon Ask for Donations
The next iteration of Plasma has reached the soft feature freeze for the 6.2 version and includes a feature that could be divisive.
-
Linux Market Share Hits New High
For the first time, the Linux market share has reached a new high for desktops, and the trend looks like it will continue.
-
LibreOffice 24.8 Delivers New Features
LibreOffice is often considered the de facto standard office suite for the Linux operating system.
-
Deepin 23 Offers Wayland Support and New AI Tool
Deepin has been considered one of the most beautiful desktop operating systems for a long time and the arrival of version 23 has bolstered that reputation.
-
CachyOS Adds Support for System76's COSMIC Desktop
The August 2024 release of CachyOS includes support for the COSMIC desktop as well as some important bits for video.
-
Linux Foundation Adopts OMI to Foster Ethical LLMs
The Open Model Initiative hopes to create community LLMs that rival proprietary models but avoid restrictive licensing that limits usage.
-
Ubuntu 24.10 to Include the Latest Linux Kernel
Ubuntu users have grown accustomed to their favorite distribution shipping with a kernel that's not quite as up-to-date as other distros but that changes with 24.10.
-
Plasma Desktop 6.1.4 Release Includes Improvements and Bug Fixes
The latest release from the KDE team improves the KWin window and composite managers and plenty of fixes.
-
Manjaro Team Tests Immutable Version of its Arch-Based Distribution
If you're a fan of immutable operating systems, you'll be thrilled to know that the Manjaro team is working on an immutable spin that is now available for testing.