IT Security - We get what we deserve?
Here we go again! It is time to STOP this!
Let's blame the human user for poor security BUT this is just like asking a car driver to stop a car at speed when the car manufacturer decided to save money by not putting brakes in the car, of course stating that the market didn't want "brakes" - metaphorically speaking. The introduction to the USA "Orange Book" of 1983 set the broad philosophy, which we have known for over 50 years, i.e. manufacturers ONLY respond to strong legislative requirements and strong government purchasing policy for secure systems. Ralph Nader did it in the 1960s for the car industry - but no-one has done it for the computer industry. Remember "C2 by '92" and even "B2 by '95"?
A quick glance at current attack problems with current systems shows that the major problem is that "Discretionary Access Control (DAC)" at the operating system level in the Internet age is totally obsolete and something along the lines of "Flexible Mandatory Access Control (FMAC)", made easy to understand and administer, is urgently needed across the computer industry.
The problem is simple!
Legislation and compliance have been common at the industry level, e.g. motor vehicles, pharmaceuticals, air transport, electric power generation and distribution and so on - BUT - for some strange reason NOT the IT industry itself.
It is time to stop blaming the customer and blame the industry.


