Martin Courtney
R E L A T E D   C O N T E N T
ADVERTISEMENT

Martin Courtney

Too much security can be a bad thing

Efforts to build solid security into software prior to release could have some unwelcome consequences

IT Week, 07 Feb 2007
ADVERTISEMENT

According to at least one expert, Microsoft’s newly launched Windows Vista is full of security holes. Plus ça change. But if web-enabled operating systems or applications could ever be made watertight, would they actually be a good thing for either developers or users of enterprise software?

Kapersky Lab’s virus analyst Alisa Shevchenko recently praised Microsoft for taking a closer look at security, and appeared certain that Vista’s developers made “a concerted effort to integrate protection against cyber threats” within the operating system.

That seems a fair assumption to make, given the vast array of programming talent at Microsoft’s disposal. However, even if Microsoft has done its level best, that is no guarantee that Vista will not be plagued by the same level of web-borne threats as XP.

It has often been suggested that application developers themselves should take responsibility for ensuring software security, rather than leaving it to third-party add-ons to fill in the gaps. There have even been calls for software companies to shoulder the burden of compensation should enterprise customers suffer data loss, outages or other revenue-sapping catastrophes as a result of hackers breaking into their systems because of vulnerable software defences.

This is partly the reason behind development tools like those being offered by Borland and Cenzic, which are designed to identify and fix vulnerabilities in source code before final versions of software are released.

But vulnerability checking within web applications can only go so far – it can never deliver a completely safe end-product that is immune to the ravages of everything the hacker community can throw at it. Any aspiring cyber terrorist needs something to shoot at before figuring out the best way to take aim, so it remains impossible for programmers to anticipate every form of attack that might ever be directed at their application.

Perhaps more importantly, stronger security always seems to come at the expense of usability, with productivity constantly being hampered by pop-up windows warning of potential threats and asking what the user would like to do.

The ability to eliminate software vulnerabilities prior to release could have another, more catastrophic affect on the development community. Many programmers rely on work writing patches and bug fixes to make a living – if the day finally comes when this skill is no longer needed, they may well have to start looking for alternative sources of work.


Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
RELATED ARTICLES
M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Computer People
Working for a growing and ambitious Professional Services company, an exciting opportunity exists for a hands on Head of IT to lead a global team and implement a best practices. Based in the centre of ... more >
| Computer People
Fantastic new opportunity for an ICT Analyst who can work without supervision to join this exciting organisation providing a lead role in maintenance and operation of their IT infrastructure and Telephone networks. The successful candidate ... more >
| Computer People
A leading UK company in the Aerospace ... more >
| Computer People
Working for an innovative and creative software company, an opening has been created for a forward thinking UNIX expert to implement leading edge network solutions into a corporate environment. Working in a team of experts, ... more >
More job opportunities