Computer Security: The better generation (2024)

To all those fine folks out there who are interested in computer security, who take care of the secrecy of their passwords and other credentials, who protect their laptops and smartphone adequately with up-to-date operating systems and antivirus software, and who apply due diligence when developing and running their IT services and/or control systems, I would issue just two words:

THANK YOU!

Thank you for reading our articles. Thank you for showing an interest in privacy and security. Thank you for wanting to learn more about this. Thank you, because you are the generation who can get it right. Or better, as my generation of 1971 didn't screw everything up.

What’s gone before
Look, for example, at an ancient telephone – the one with a rotary dial. Back then, fear of being spied on was minimal, and only an issue if you annoyed your country. Today, we all carry small spying devices around that collect all our personal information and pass it on. Maybe not immediately to governments, but to big multinationals that make money from our personal data. The secrecy of the post has become WhatsApp, Threema, Signal and Telegram – each with their own privacy-preserving means (or not). With the cloud came the Wild West. Analogue cameras became Instagram and TikTok. Apple revolutionised our record and tape collection. CDs? Bah. MP3s? Not anymore. Linear television became Netflix, Amazon Prime and Disney+. Amazon and Google know much more about our shopping habits than the old neighbourhood shopkeeper ever did. And workout information now goes to Strava, Fitbit or the like. Mapping out the world. Our nicely cloaked private world has become frighteningly transparent and public. Orwell’s 1984 surveillance state at its best. At least there is a silver lining in the form of the European Union’s General Data Protection Regulation, which the big companies try to aggressively bend and small startups try to creatively circumvent.

Like with privacy, digitalisation over the past decades has tied our lives into symbiosis with technology. Physical security has become cybersecurity. Today, all the amenities of life are technology-supported. Depending where you are, this is the case to varying degrees. Consider electricity. In most of our countries, electricity is the One Ring that rules it all. No electricity, no cold food or (worse) medication. No electricity, no communication. No electricity, no fresh water, as water pumps need electricity. Similarly for fuelling stations. No electricity, no public transport. Going shopping? Erm, how did you pay last time? Of course, you might have some batteries left over, or a diesel generator. But in the long run? We live in symbiosis with a technology backbone. With electricity. With the control systems deployed for running this backbone. In the past, this backbone was threatened only by physical means – by conflicts. By nation states in an increasingly peaceful world. While we thought that those times were gone, our backbone is now much more susceptible to threats. No need for nation states anymore, when a small group of (state-sponsored) criminals can create havoc. Like the attacks on Saudi Aramco. Like Stuxnet against Iranian nuclear centrifuges. Like Russian hackers allegedly attacking Ukrainian infrastructure prior to the invasion of Crimea. Like the ransomware attacks against Maersk. Like the Conti ransomware group against anyone else on this planet. The COVID-19 pandemic and Russia’s war against Ukraine have shown how fragile our technological backbone has become, how inherently insecure it is and how easily it can be brought to a halt. Threats to this backbone won’t disappear.

And the future, the sunny world of clouds, requires even more backbone. More interconnectivity, more technology, more complexity. Ergo more vulnerabilities. And ergo more severe consequences. Self-driving cars talk to each other and to the traffic lights. Cities become smart. Cashless stores RFID your shopping basket and charge your credit card automatically. Your fridge orders missing items automagically, delivered by drone within 10 minutes. In this brave new Wild West, the genie is out of Pandora’s box. Our technological backbone needs reinforcement. The stupid internet of unsecure things needs improvement. The zillions of layers, virtual machines, containers, software interdependencies, agility, DevOps and just-in-time need experts to put the genie back in the bottle. To adapt technology such that it serves but does not burden. To bring security into every single layer by default. Making security an equal among other IT equals: functionality, usability, maintainability, availability and – security. While threats and threat actors will never give up (and will actually become more and more sophisticated), we need to counter the increasing number of vulnerabilities and keep the consequences of successful attacks at bay.

Now, enter you!
We will never have 100% secure systems – and those who promise this to you are either liars or salespeople or both. “Security will always be exactly as bad as it can possibly be while allowing everything to still function” (Nat Howard). Because we’re lazy and ignorant, because security is usually just a cost factor with limited benefits: security, convenience, cost – pick two. This makes security only as good as the weakest link in the chain of technology. This makes security a people problem. But this also makes security a problem that can be solved by people. You are the crucial generation. The first twists and turns towards a more privacy-preserving and secure future have started. Facebook and Google have been restrained from collecting data. WhatsApp becomes Threema or Signal. Security must again move into focus, joining the other —ities and reinforcing the CIA triangle: confidentiality (hush! for your personal life), integrity (your bank statement) and availability (giving you electricity when you need it). Actually, in industry this is instead the AIC triangle (availability: your supermarket; integrity: the soundness of the bridges you cross to get there; and confidentiality: Coca Cola’s secret recipe).

Since my generation failed to consistently, coherently, efficiently and effectively push those triangles through as it should have, the baton is now handed to you. Together, let’s break up the old mantra of “freedom, security, convenience – choose two” (Dan Geer) and see how we can still get all three deployed on an acceptable level. Open your mind to think secure and privacy-preserving. If you haven’t done so yet, learn how to prevent and protect, how to plan, design, develop and build secure and privacy-preserving applications, software and systems. How to operate systems in a secure and privacy-preserving fashion – finding weaknesses and vulnerabilities, detecting abuse and ensuring that sufficient log information is at hand, and using the magic means available to understand what happened if the evil bad has compromised your system: forensics, incident coordination and response.

In addition to the new round of WhiteHat and Zebra training sessions, which are coming up very soon, we’re happy to announce that dedicated online training courses on all security matters are now available to all of you at any time, with our thanks to the HR training team. The SecureFlag training platform provides hands-on courses, exercises and virtual environments for you to improve your skills in secure software development in your favourite programming language (demo video). Learn how to securely configure your systems, virtual machines and containers and how to securely operate your web and computing services. These new, dedicated courses are provided for your benefit and for the benefit of a secure organisation – to clean up the security and privacy mess. THANK YOU!

______

Do you want to learn more about computer security incidents and issues at CERN? Follow our Monthly Report. For further information, questions or help, check our website or contact us atComputer.Security@cern.ch.

Computer Security: The better generation (2024)

FAQs

What are 3 reasons computer security is important? ›

The security precautions related to computer information and access address four major threats: (1) theft of data, such as that of military secrets from government computers; (2) vandalism, including the destruction of data by a computer virus; (3) fraud, such as employees at a bank channeling funds into their own ...

Why computer security is important nowadays? ›

Cybersecurity is important because it protects all categories of data from theft and damage. This includes sensitive data, personally identifiable information (PII), protected health information (PHI), personal information, intellectual property, data, and governmental and industry information systems.

What are the five types of computer security? ›

The Five Different Types of Cyber Security
  • Application Security. ...
  • Network Security. ...
  • Cloud Security. ...
  • Critical infrastructure security. ...
  • Internet of Things (IoT) Security. ...
  • Build your cyber security strategy with Office Solutions IT.
Mar 20, 2024

How useful is computer security? ›

Computer security protects individuals and organizations against cyber threats and the loss of important data. Becoming the target of a cybercriminal can be incredibly damaging and disruptive to daily activities, whether personal or professional.

What are the 3 A's of computer security? ›

Authentication, authorization, and accounting (AAA) is a security framework that controls access to computer resources, enforces policies, and audits usage.

What are the top 3 computer security trends? ›

  • Trend 1: Increased Focus on AI and Machine Learning in Cybersecurity. ...
  • Trend 2: Growing Importance of IoT Security. ...
  • Trend 3: Expansion of Remote Work and Cybersecurity Implications. ...
  • Trend 4: The Rise of Quantum Computing and Its Impact on Cybersecurity. ...
  • Trend 5: Evolution of Phishing Attacks.
Apr 1, 2024

What are the advantages and disadvantages of computer security? ›

Cyber security measures can aid in the prevention of cybercrime, the enhancement of data privacy, the promotion of company continuity, and the growth of customer trust. However, establishing strong cybersecurity safeguards can be costly and complicated, and there is always the possibility of human mistakes.

What are two safety tips for computer security? ›

"Top 10" List of Secure Computing Tips
  • Tip #1 - You are a target to hackers. ...
  • Tip #2 - Keep software up-to-date. ...
  • Tip #3 - Avoid Phishing scams - beware of suspicious emails and phone calls. ...
  • Tip #4 - Practice good password management. ...
  • Tip #5 - Be careful what you click. ...
  • Tip #6 - Never leave devices unattended.

Why security is the most important? ›

Security measures enhance safety, prevent incidents, protect property, and contribute to the overall well-being of individuals and communities. Let's appreciate the efforts of security professionals and work together to create a secure and harmonious society for everyone to thrive in.

What are the 5 C's in security? ›

Change, Compliance, Cost, Continuity, and Coverage; these are all fundamental considerations for an organization. For anyone challenged with evaluating and implementing technical solutions, these factors provide a useful lens through which to assess available options.

What is the most basic rule of Computer security? ›

Choose a strong password

Login password is often the first line of defense against unauthorized access to your computer. Computers with no password, or an easy to guess password, can be quickly broken into. Choose a secure password for every account.

Who is the father of Computer security? ›

August Kerckhoffs: the father of computer security - History | HEC Paris.

What is the main purpose of computer security? ›

Computer security has three main goals: Confidentiality: Making sure people cannot acquire information they should not (keeping secrets) Integrity: Making sure people cannot change information they should not (protecting data) Availability: Making sure people cannot stop the computer from doing its job.

Should I get security for my computer? ›

Although some devices may have built-in protection against viruses, using third-party antivirus software is a necessity, be it free or paid.

What is computer security in simple words? ›

Computer security basically is the protection of computer systems and information from harm, theft, and unauthorized use. It is the process of preventing and detecting unauthorized use of your computer system.

What are 3 major security concerns for computer systems? ›

Types of Computer Security Threats and How to Avoid Them
  • Computer Viruses. Perhaps the most well-known computer security threat, a computer virus is a program written to alter the way a computer operates, without the permission or knowledge of the user. ...
  • Spyware Threats. ...
  • Hackers and Predators. ...
  • Phishing.

What are the three 3 features of security? ›

The importance of the security model speaks for itself: Confidentiality, integrity and availability are considered the three most important concepts in infosec. Considering these three principles together within the triad framework guides the development of security policies for organizations.

What are the 3 important key security concepts explain them all briefly? ›

Three basic security concepts important to information on the internet are confidentiality, integrity, and availability. Concepts relating to the people who use that information are authentication, authorization, and nonrepudiation.

What 3 things can help to protect the security of your computer? ›

Antivirus software, antispyware software, and firewalls are also important tools to thwart attacks on your device.
  • Keep up-to-date. ...
  • Antivirus software. ...
  • Antispyware software. ...
  • Firewalls. ...
  • Choose strong passwords. ...
  • Use stronger authentication. ...
  • Be careful what you click. ...
  • Shop safely.

Top Articles
Latest Posts
Article information

Author: Mr. See Jast

Last Updated:

Views: 6224

Rating: 4.4 / 5 (75 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Mr. See Jast

Birthday: 1999-07-30

Address: 8409 Megan Mountain, New Mathew, MT 44997-8193

Phone: +5023589614038

Job: Chief Executive

Hobby: Leather crafting, Flag Football, Candle making, Flying, Poi, Gunsmithing, Swimming

Introduction: My name is Mr. See Jast, I am a open, jolly, gorgeous, courageous, inexpensive, friendly, homely person who loves writing and wants to share my knowledge and understanding with you.