Sunday, April 27, 2008

Security through obscurity is easy, I have security through mystery

I have found in my travels that more often than I would like people have interpreted security as needing to be so complex that not even they understand it. “Well if I plug this in over here and then close my eyes and plug the other end over there we should be secure.” Security should be clean and simple. I know that the vision of some teenage kid in his pj’s hacking away when his folks think he’s asleep terrifies us all, but come on, who are you fooling. Making security complex only means that you spend less time working on your systems to confirm that they are patched and up to date, or even really working. When testing out a new security product you should find out how much time it will take to manage and how it will make your life easier in the long run.

