16
February
2005
|
17:13 PM
America/Los_Angeles

RSA security conference: A cacophony of FUD...could someone please call the investment bankers

by Tom Foremski for SiliconValleyWatcher

Where are the investment bankers when you need them? Could somebody please roll up a bunch of these computer security companies? And why isn’t it happening? Are the VCs holding out to get better valuations?


The RSA Security conference is in SF this week and although I tried to avoid it I did get dragged into a few events. The main problem with this sector is that there are way too many security companies. And they try to stand out from each other in two ways: slam the competition, and shout that the sky is falling. That means they are undermining each other’s solutions and the market as a whole, creating confusion and delaying purchase decisions.


Shouldn’t we have some kind of baseline security standard to benchmark against? I bet I could buy every security product out there, and still, someone would come around the next day and tell me I’m vulnerable to some exotic exploit. How do I reliably check those claims?

For example, TriCipher hosted an event at which Becky Bace, demonstrated a new “middle man” phishing attack that she said kills the security token. Now Becky is an interesting person, she used to be at the National Security Agency and is a well recognized and respected member of her community. Her demonstration of the “middleman” phishing 2.0 scheme was interesting, but, as Deb Radcliff, a veteran computer security reporter asked in the Q&A, how credible is it that someone would perform a manual hack like that? She was told that it was possible and that this was a huge vulnerability.


But, is it being done? What are the likeliest attacks? What are the best practices? There is way too much FUD in this industry because there are too many players creating a din.




Here is the promo material on the TriCipher event and Becky:


World renowned industry expert Becky Bace showcases Phishing 2.0, a short but eye opening talk and real time demonstration on one of the latest phishing threats. Hackers are moving from plain old password harvesting to sophisticated attacks that easily defeat all known passwords, tokens and one-time-passwords. Becky expects that such session perversion attacks, which first began to be observed a few months ago, will become a dominant attack vector for phishers.




Becky is an expert on intrusion detection with over 15 years’ experience in network security, including 12 years at NSA, and she has written several influential books on this and other security-related topics. Becky is CEO of Infidel, Inc. and Venture Consultant for Trident Capital.