Why Is There Reason for Cybersecurity Optimism?

1.5K views
•
February 26, 2013
by
RSAC Cybersecurity
YouTube video player
Why Is There Reason for Cybersecurity Optimism?

TL;DR

Cybersecurity optimism is justified by concrete progress in trusted hardware, secure software development, identity management, operational security, and market demand. No single technology or organization can solve every problem, but hardware-rooted trust, scalable development practices, standards, compliance requirements, and customer contracts are creating foundations for stronger security across devices, applications, services, and cloud environments.

Transcript

Said President Nixon upon seeing the new Sears Tower, "Wow, that is a big tower." And now I'd like to introduce a new segment of our show, Bright Side Security News, where we bring you the good news in cutting edge computer security. Computers, they are a big deal, and if you're a punch card operator, your future is looking good. However, computers... Read More

Key Insights

  • Cybersecurity optimism is supported by practical advances that improve security today while establishing foundations for stronger protection tomorrow. The argument does not depend on eliminating every attack, but on recognizing sustained progress across hardware, software development, identity, operations, compliance, standards, and market behavior.
  • Hardware-rooted trust is becoming a stronger foundation for system security through UEFI, trusted boot, and measured boot. These capabilities can help determine whether a machine started in an expected state and produced the anticipated cryptographic result, or whether its startup environment may have been altered.
  • TPM-based authorization can provide machines with verifiable identities across networks. This creates opportunities for systems to assess the devices they connect with, combining machine identity with boot measurements to support more informed judgments about device health and trustworthiness.
  • Earlier loading of anti-malware products can help address rootkits lower in the technology stack. Placing defensive capabilities closer to the beginning of the startup process makes hardware and boot security more useful as a foundation for protecting the operating system and applications above them.
  • Secure development life cycle practices are being adopted by organizations seeking to produce more secure operating systems and applications. Their significance lies not only in defining good security practices, but also in showing that those practices can be applied broadly across engineering teams and products of different sizes.
  • Standardization is essential because attackers seek weak links across interconnected technologies and organizations. A common secure development framework can raise expectations throughout the industry, help more developers adopt consistent practices, and create a basis on which organizations may eventually demonstrate or certify conformance.
  • Customer contracts are becoming a mechanism for demanding secure software development. When purchasers include secure development requirements and select vendors capable of satisfying them, security becomes a market concern rather than only a technical aspiration, encouraging wider adoption of established engineering practices.
  • Identity systems must balance reliable identification with anonymity where free speech or controversial expression requires it. Effective identity management also depends on coordination among the parties that verify people, issue credentials, present credentials, and rely on those credentials during transactions.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: Why is there reason for optimism about cybersecurity?

There is reason for optimism because multiple parts of the security ecosystem have advanced together. Hardware can provide trusted and measured startup processes, organizations are adopting secure development practices, standards are making those practices easier to spread, and customers are requesting security requirements in contracts. These developments improve present defenses while creating foundations that future systems can build upon.

Q: How do trusted boot and measured boot improve security?

Trusted boot and measured boot help establish whether a machine started in the expected condition. A measured startup can produce a cryptographic result that systems compare with the expected result, helping reveal whether the machine may have been altered. These capabilities allow security decisions to begin with hardware and startup integrity rather than relying entirely on software that loads later.

Q: What role does TPM play in network security?

TPM technology can support machine identity and authorization between devices across a network. When combined with measured boot, it can help a system identify the machine it is connecting to and evaluate evidence about how that machine started. This creates a stronger basis for assessing device health and deciding whether a connection should be considered trustworthy.

Q: How can early anti-malware loading help prevent rootkits?

Loading anti-malware products earlier in the startup stack gives defensive software an opportunity to operate before threats can become deeply established in the system. Scott Charney identifies this capability as important for addressing rootkits, which had been a significant problem. It also demonstrates how hardware and boot improvements can support protections used by operating systems and applications.

Q: Why is a secure development life cycle important?

A secure development life cycle incorporates security practices into the process of building operating systems and applications. Its value includes producing more secure software and making security repeatable across engineering organizations. The Microsoft experience described in the keynote emphasizes scalability, showing that secure development concepts can be applied across many engineers working on both large and small products.

Q: Why does standardization matter for secure development?

Standardization gives organizations and developers a shared description of what secure development involves. This can promote broader adoption, help raise security practices across the industry, and provide a future basis for certification. Broad improvement matters because attackers target weak links, so isolated excellence cannot protect an ecosystem when other connected products or organizations remain vulnerable.

Q: How do contracts encourage vendors to build secure software?

Contracts can turn secure development into a condition of doing business. Customers can include language requiring vendors to follow secure development practices, then look for suppliers capable of meeting those requirements. This creates market pressure that supports deployment of available security capabilities and helps align technical progress with the economic incentives needed for broader adoption.

Q: What makes digital identity management difficult?

Digital identity management requires several parties to coordinate. One party may conduct in-person proofing as the root of a credential, another may issue it, a person must present it, and an organization must rely on it. Adoption becomes difficult when users are asked to obtain credentials that merchants or governments do not yet request, even when the technology already exists.

Summary & Key Takeaways

  • Scott Charney argues that optimism about cybersecurity can rest on measurable industry progress rather than wishful thinking. Although the internet was built without security as a central concern and attacks continue to evolve, companies, governments, researchers, and standards bodies have developed technologies and practices that strengthen both current systems and future security foundations.

  • A trusted technology stack begins with hardware-rooted security and extends through operating systems, applications, and identity services. UEFI, trusted boot, measured boot, TPM-based machine identity, and earlier anti-malware loading can help verify system health, identify altered machines, and address threats such as rootkits before higher software layers operate.

  • Secure development practices are spreading across major organizations and becoming standardized, scalable, and commercially important. Standards can help more developers adopt consistent methods and eventually support certification. Meanwhile, customers increasingly place secure development requirements in contracts, creating market incentives that encourage vendors to build security into software throughout the development process.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚