What Did RSA Conference 2010 Reveal About Security?

TL;DR
Cloud computing was presented as an irreversible shift that could reduce maintenance costs, change IT roles, and require virtual machines to be secured at the hardware level. Other major themes included privacy-controlled digital identities, legal action against botnets, reputation-based protection, data ownership, and homomorphic encryption that could allow data processing without decryption.
Transcript
Uh, we had a, a very good, uh, start to the day. And then, uh, the first award was, uh, Whitfield Diffie, you know, Diffie-Hellman, Diffie. So he got the, um, lifetime achievement award. And, um, then Art Coviello, um, took the stage, uh, from EMC RSA. And, uh, the topic was, again, cloud computing. And, uh, basically, what he said was real. He sai... Read More
Key Insights
- Cloud computing was presented as an irreversible transition comparable to society's movement from barter and physical currency to virtual money. Although virtual systems retain security risks, the argument was that organizations will not return to older computing models after adopting cloud infrastructure.
- Cloud adoption could reduce the maintenance burden that consumes two-thirds of IT budgets, according to the conference recap. Redirecting part of that spending could give organizations more capacity to deploy new systems and pursue work that existing infrastructure and operating models made difficult.
- Traditional IT roles are converging as virtualization expands administrative responsibilities. A virtual-machine administrator may also perform network and desktop administration, making the work more complex and changing how organizations define security, infrastructure, and operations jobs.
- Virtual machines must be protected at the hardware level, according to Art Coviello's announced initiative. RSA, Archer, EMC, Intel, and VMware planned to collaborate on delivering security for virtual machines directly at the chip and physical hardware layer.
- Digital identity systems can give individuals greater control over private information. Microsoft's German eID case study involved a local provider and Germany's Ministry of Interior, with controlled identity data determining who may view a person's private details.
- Botnet disruption can combine legal mechanisms with technical security controls. Microsoft's case study showed how legal action was used alongside technical capabilities to take down one of the world's largest botnet systems and counter malicious Internet activity.
- Data-centric security begins with applications or the data itself rather than relying only on secured desktops. Symantec connected this approach to governance, risk, and compliance and introduced Data Insight to identify ownership, access permissions, broadly accessible file shares, and access-control changes.
- Homomorphic encryption allows work to be performed on data without decrypting it, according to the recap's interpretation of the cryptographers panel. The concept was presented as an important encryption breakthrough with clear relevance to services that process or analyze stored information.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: How could cloud computing reduce IT maintenance costs?
Cloud computing could reduce the portion of organizational spending devoted to maintaining existing systems. The recap states that two-thirds of IT budgets were going to maintenance, leaving fewer resources for new capabilities. By lowering that burden, cloud infrastructure could help organizations deploy systems they could not previously implement and redirect resources toward new work and services.
Q: Why was cloud computing compared with virtual money?
Cloud computing was compared with the evolution of money from barter to precious metals, coins, paper currency, and finally virtual transactions. Virtual money creates uncertainty about where value resides, just as cloud computing raises questions about where data resides. Both still face security threats, but the comparison suggests society will retain virtual systems rather than return to older physical exchanges.
Q: How will cloud computing change information technology jobs?
Cloud computing and virtualization will cause previously separate technical roles to converge. The recap describes a virtual-machine administrator as also functioning like a network administrator and desktop administrator. This combination makes administration more complex and suggests that familiar job definitions will change as responsibility for computing, networking, endpoints, virtualization, and security becomes increasingly interconnected.
Q: How can virtual machines be secured at the hardware level?
Art Coviello announced an initiative intended to deliver virtual-machine security at the hardware chip level. RSA, Archer, EMC, Intel, and VMware were identified as participants in the collaboration. The goal was to protect virtual machines closer to the underlying physical hardware, described as the metal, instead of relying exclusively on controls operating within virtualized software environments.
Q: What privacy benefits did Germany's eID project provide?
Germany's digital identity card project was designed around controlled identity data. The joint effort involved Microsoft, a local provider, and Germany's Ministry of Interior. Its privacy benefit was that individuals could control who was permitted to view their private information, creating a more selective identity-sharing model instead of exposing every personal detail whenever identity verification was required.
Q: How did Microsoft combine legal and technical methods against a botnet?
Microsoft presented a case study about taking down one of the largest botnet systems in the world. The important lesson was that malicious Internet activity was not addressed through technical controls alone. Microsoft also used the legal system as part of the disruption effort, demonstrating that effective action against large online threats can require coordinated legal and technical measures.
Q: What does Symantec Data Insight do for data security?
Data Insight was described as the next level in data loss prevention and as a tool supporting governance, risk, and compliance. It automatically identifies who owns data and who can access it, finds file shares that everyone can reach, and records who changes access controls. These functions help organizations understand responsibility, exposure, permissions, and changes affecting sensitive information.
Q: What is homomorphic encryption according to the conference recap?
Homomorphic encryption was described as a method that allows work to be performed on data without first decrypting it. The recap identified it as a breakthrough discussed during the cryptographers panel and highlighted its relevance to organizations that process data. The speaker advised searching the term for more information while acknowledging that this description reflected his own understanding of the concept.
Summary & Key Takeaways
-
Art Coviello described cloud computing as a way to deploy previously impractical systems while reducing the two-thirds of IT budgets reportedly spent on maintenance. He also announced collaboration among RSA, Archer, EMC, Intel, and VMware to provide virtual-machine security at the hardware chip level and address changing administrative responsibilities.
-
Microsoft presented new identity-management initiatives, an acquired system being released as open source, and Germany's eID project, which lets individuals control access to private identity information. Its keynote also showed how legal mechanisms could supplement technical controls when disrupting a major botnet and combating malicious activity online.
-
Symantec advocated information-centric security, reputation-based protection, governance, risk, and compliance controls, and its Data Insight solution for identifying data ownership and access. A cryptographers panel discussed broken algorithms, RSA 768, the transition toward 1024, homomorphic encryption, and tensions between academic researchers and the government security community.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator