A colleague on a listserv recently posted a response to this question that can be summarized by the following:
“I really think the weakest link in our computers now sits in the chair in front of the keyboard.”
I fundamentally disagree with this statement and retorted with the following:
On some level you are correct; however, some of the fundamental issues that I'm observing are the damage that semantics is causing. As a result of marketing we have various "Antivirus" programs, while at the same time those vendors offer additional packages as "anti-spyware" and "anti-malware". It is wrong of us to shift the responsibility onto the end user as we are inherently responsible for lulling them into a false sense of security (e.g. we supply antivirus and make them update so they are safe). Yes, users need to understand not to allow certain things to install and, at some level, I believe we see they understand that fact. Where we should be placing pressure/blame is on the "anti-virus" vendors. The whole marketing "anti-virus" only treating "viruses", anti-spyware only treating "spyware" is an antiquated notion and ultimately hurts the end user. Malware, viruses, worms, plague, at this juncture it's all the same.
We've seen a paradigm shift in the nature of the threats and the roots of infection. We've adapted, many of the major vendors as a result of marketing have not. Every machine that has come through our auspices has been patched and up to date with the latest dat files from Network Associates [8.5 and 8.7]. However, this has done nothing to reduce, stop or inhibit the spread of Windows Antivirus 20XX, AV360 or the various evolving rootkit style infections.
In short, the products we have purchased to protect our users have failed to evolve with the needs/threats to our users.
-J

No comments:
Post a Comment